Techstrong TV – May 12, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. Have we broken the internet again? You're watching Textron Gang.
Hi everyone, it's Alan Shimel, and happy Monday to you all. I hope you all had a great weekend. I did.
You're watching Text on Gang, you know, uh, we've got a great week this week of Text Strong Gang. I'm excited. I've got a lot of stuff going on here at Techstrong.
There's a lot of stuff going on in the industry. We're gonna hear from some of our gang members what they've got going on, but there's a lot going on out there too. Can't wait to talk to you about it.
Let me introduce you to our gang for today. First of all, I don't know if he is also in DC going either the portrait, uh, gallery tour or back home in Austin. Guy Currier of Futurum and vi well, VI Principal Analyst.
How are you guy? I'm real good. Thanks.
I'm actually on my way out in your direction, out heading out your direction. So I'm at the airport heading to Orlando for the Click Connect conference. So That's why Very cool, very cool.
On a weekend. Uh, it is. Does Monday count Weekend?
Well, it's Monday. Yeah, that's true. It's gonna be another busy week on Click Connect.
Very cool. All right. Moving from Guy, one of our newest gang members, but our, one of our cyber cyber sleuths, Teri Robinson.
Hey, Terry, how are You? Hi, I'm great, uh, on this sort of rainy New York Day. Oh, it's rainy.
I'm sorry. That's okay. But, you know, well, I was gonna say it's April showers May flowers, but it's may already isn, isn't it?
It's May. That's right. Looking for those flowers.
Yep. Good for you. All righty.
Joining us. Uh, I'm gonna assume he's home in Guitar Land, not Nashville. Denver.
Mitch Ashley Fu, VP DevOps Analyst. Hey, Mitchell. How are you, man?
Doing good. Just working in the guitar store this day, you know, we'll open the doors and have some folks come in and do a little Selling coming up here. No, no, it's not the guitar store.
Well, look, man's gotta make a living. Um, you know. Yep.
And then he's still in DC it looks like from the looks of things. He's our Chief Content Officer, Mike Vizard, that has a distinct look of a hotel room, doesn't it? And it is distinctly a hotel room.
Yes. It's one of those, you know, westins, that book alike, no matter what city you're in, they all look the same. Yeah.
But they all have a great bed. Yeah, that's true. Right?
Um, yeah. Hey, Mike, how are you? I'm well.
I'm looking forward to taking the train home this afternoon. And, you know, I keep asking them to let me drive, but they keep saying no. Tell 'em your name's Choo Charlie.
I don't know if that might be a little over some of you, but, um, anyway, let's, let's move along. So, is the internet broken again, Mike? Have, has, has our encryption failed?
What's going on? So there's this research paper coming outta China, and it's only a research paper, so I don't think we should freak out just yet, but it suggests that we can now predict the sequence or order of which prime numbers might come through. And that's kind of the key to how all of our encryption works.
So this could be a significant problem. Terry, I know you looked into it and you're a long time, uh, follower of all things cybersecurity. What's your take Here?
Well, first I wanna say that I feel like everything I believe from childhood is slowly being dismantled. Um, now it's, we're talking about prime numbers. Um, my, my, uh, recently departed math teacher, Sandra McCall is probably, uh, looking down.
And, um, so these researchers in, uh, in, uh, Hong Kong and, uh, in the United States published a paper. And basically what they said is prime numbers aren't as random as we thought that they, they were. Um, and they actually also included sort of, um, a periodic table of primes, which is, uh, a lot like the chemistry periodic table.
And, um, you can predict what the next prime is gonna be, and you can do it relatively quickly, which has the potential then to, to, uh, upend, um, encryption because that's behind, uh, you know, RSA and, and just about every other en encryption form that we have. So, um, that's why people are talking about it. Um, whether or not it turns out to be a big, uh, blow up or not is, is definitely in question.
Um, it's something to look at. And if it's not gonna be this, it's gonna be something else like quantum computing that's probably gonna, um, mess up, uh, uh, encryption as we know it today. So, do I have this right now, I'm also looking at these new LLMs and they all have more advanced reasoning capabilities, and some of them can do math now.
So rather than waiting for quantum, will somebody just take one of those and start applying it to predicting random numbers? And we could be in a lot of trouble Together. We think.
Oh, yeah, no, I mean, depending on who you talk to about this particular issue, that's, that's the case. Some people are like, okay, maybe it's not gonna be so bad. And other people are going, well, in fact, with, um, you know, the large language models and everything, it's, it could be a lot faster than we thought.
Um, without that, um, quantum is expected to sort of upend things within the next decade, I would say. Um, it's gonna be quicker than that. Right.
And Alan, as you well know, the bad guys are harvesting the encrypted data now on the assumption that they're gonna crack it later. So, you know, all our secrets are gonna be out there one way or another. They're, they already are.
They already are. Let, let's be real. But look, here, here's my take on this one.
Let's not run around yelling that the sky is falling and the internet is broken just yet. There, there's a, there's a long way away from saying I could predict what the next prime number is. And using an LLMI could predict the next prime number faster than humans can to actually using that to break, let's say an RSA algorithm.
Encrypt encryption algorithm. There's a lot, you know, using normal computers, not super duper crazy computers that maybe the NSA has to brute for some of these RSA certificates would take like hundreds of years. And so maybe using this technology, it only takes 35 years.
Okay? I'll live with 35 years. Quantum is much, is a, I think a much more deadlier, uh, threat to modern encrypt to present day encryption, because in quantum it has the promise of breaking it in a few minutes, right?
And, but here's the good news. Here's the good news for once NIST and, and, and mire and, and the industry appear to be out ahead of this, and we've got these post quantum algorithms that are already finding their way into DigiCert certificates, for instance, and some of the other certificates that are being used out there. And we're, we're making certificates that expire a lot faster, right?
We're expiring our certificates now, not in 90 days or 180 days or a year, but we, we want 'em, they want us get down to expiring them every month. So you are going to be updating to the latest technology in your certificate encryptions. Now that information that, you know, like hash, you know, bundles of, of info every day that goes by, that information becomes less and less valuable because it's less and less current and less and less correct.
So, you know, we've got a new American Post Pope peace beyond to all of you. Don't, don't worry just yet. I don't, I don't, I think this is a red hairy.
You know what it, Terry, it reminds me of what you were saying about, you know, the thing, all the things you believed in, kind of being disproven. Take me back to math. Math in high school and college where we looked up random numbers in a table in a book.
They're really just pseudorandom. They weren't really random. Um, but if we have a periodic table for prime numbers to be able to predict that, it's really, it doesn't take an AI system to do that once you've got those, that table out, right?
So this something that widespread use, and, and I think I remember I weren't they calling it like crypto agile or some kind of a algorithm, is what n is working on. And course there's also not just, um, quantum breaking current encryption, but also quantum encryption, which would be, you know, that much more difficult to break with anything. So I'm glad to hear, Alan, that you see this as a kind of a nen burger from a cybersecurity standpoint.
I'm just blown away from this, a mathematical standpoint From mathematics. This is big news. This foundational elements of mathematics is, I I agree.
Unpredictability, All of our math teaches is Pattern and prime numbers. Yep. Um, makes me think of Cold Fusion as a, as a non-expert and wonder if it's gonna be, you know, uh, disproved or refuted, you know, WW soon enough.
I, I just, you know, we should take a moment, all of us to think e even if you not an expert in math, how fundamental the concept of how prime numbers work is going back centuries and there being a different way that they work, uh, could easily have much bigger imp implications across it, honestly, including in quantum, uh, that we couldn't predict right now. So It'll be interesting. And I, I do agree, Terry.
I think all of our math teachers are spinning, spinning in their graves over this, right? I mean, it is like, I dunno, you know, shaking the foundation. I think we're in trouble deep himself.
I think we're in trouble deep if we're counting on the Pope to say a prayer for us at this point. 'cause usually that's the last thing that you say when you got Right, when all else fails, turns to God tweet. So we have po tweet, so, you know, tweet us, he tweet us.
Well, I, I don't know. I'm, I'm sorry I took us down that path. I apologize.
I I was bringing religion into it. I was gonna say too, I mean, it's also not like the industry is standing still on this. Um, you know, and just seeing where it spins out and the work that NIST is doing is, is, uh, you know, quite interesting and, you know, and ongoing and, and it kind of gets away from that single assumption that all of this has been, you know, based on before.
And, and, uh, I think, you know, maybe there's gonna be some movement there that, that counters whatever might come from, um, from, uh, prime numbers not being random anymore. But, um, yeah, we'll see. Um, it's, it's up in the air right now, but it's something to follow, right?
And look closely at as we go forward. I, I'm interested to see the mathematicians weigh in as well. Yeah.
No, I'm, I'm look and research is good. I'm, you know what that, that's why it's important to fund research just for science cycle alone, right? 'cause you don't know what you're gonna turn up and what the commercial applications of it will be.
Anyway, let's take a break here on text and gang. Let's come back. And we're talking Nats not the Washington Nationals, but you're watching Text on Gang.
Hey folks. We're back. And we're talking about another one of those instances where somebody decided they had open source regret maybe, and they were gonna try to take back their project.
And there was a big kerfuffle over this. And then it turns out that the, it's still open source, but it's a slightly different, uh, flavor of it, maybe. Or they came to some agreement about the trademarks.
We'll get into the details, but it involves something called Nats, which as I understand it, is a framework for communications across clouds involving APIs and microservices. And it's a, from an outfit called, uh, Sonata. And, um, most people never heard of either one of these companies until this happened, Mitch.
So, you know, is this kind of like, you know, marketing in some level? Well, it, it's my third generation of Nats. Of course, there's the Nats that fly around then network, ad address translation service, which is a networking thing that gives you an address that you can, don't, don't need to get from the internet.
And, you know, as you said, you said it really well, you nailed it. You know, it's a communication substrate, uh, for talking across cloud, between microservices, kind of interservice communication. 9% of the world wouldn't know what it was, even if you explained it to 'em.
'cause they don't need to know. And it's not that important. But, but it is important because, um, NATS has a, a lot of capabilities built into it.
And it's used in, in a number of, uh, pieces of software. It's also got like a, a streaming capabilities, like a Kafka kind of solution. And so this keeps it in, uh, in the CNCF governance structure, the support, certification, all that kind of thing.
Um, so it also, there was also at least some trademark issues too that were coming up about that and how that, whether that can be transferred to the Lennox Foundation, you know, all the lawyers, I guess the Pope got into it, and all the lawyers, you know, calmed down and, and agreed to whatever they agreed to so they could, so they could keep this open source. But, but this is a great example of the flexibility in open source, right? So you got this company that, as Mike said, maybe had some open source remorse, right?
My God, why did I release this open source? I could have been making money on all these things, and we're not, you got the community and the LF and everyone up in arms about them looking a pull. You, you once it, you know, it's like that butterfly leaving your hands once it's outta your, or Jonathan Livingston Seagull, for those of you who remember, once you set it free, if it comes back, it's yours.
If it does it, it never was. And, and so it's out there now as, as there, there's a link to an article in the register. And as usual, your, your register takes a snarky, snarky title for clickbait.
They didn't tell 'em to fork off, but, but you are always free to fork an open. You wanna take, you wanna take an open source project and fork it and maybe close that off from that point forward changes you make. But you, you do that.
You, you get try doing that, right? The half the security industry was doing it when Mitchell and I were doing still secure, right? Under the covers, it was all snort or Nessus or Nmap, or a combination thereof.
It's the way of the world. There's nothing, nothing new here. Move along.
Uh, but we didn't have things like the Linux Foundation and the CNCF back then that would give these orphaned projects that their, you know, commercial originators were looking to move away from or buried deep, um, a place to live. And, and that's one of the nice things about today's open source world, is you do have the lf, the Apache Foundation, the CNCF and others that give these, these projects a home that own the IP that do make sure that there will always, there is an open source version that is gonna be continued to be developed, right? Because right, like when Tenable stopped making an open source, Nessus, Nessus, what was it?
4, Mitch? Yep. 7.
Not an open source anyway. Right? I still feel like though, um, the, the bigger issue here is what's most, you know, salient, which is, um, I, I still feel like no, no vendor has really figured out how to profit from open source.
Let, let's divide open source standards or open standards, sorry, from open source software. We're talking about open source software here, things with licensing, so forth, even open source software as licensing. Um, I, I, you know, Cincinnati is based complaint, right?
Was, uh, this is our, the nobody's come to play with us. So we're doing everything for this. And, uh, why should we just give our engineering away for free?
Let's, we're gonna, we want to take it back. No, no one is, that's why it's so important, Mitch. I think that's why it's so important, because somehow it's unimportant enough for there to be a lot of contributors.
Meaning, meaning, uh, other vendors or, or institutions even, you know, public institutions. They're not investing in, you know, development talent to really get what's going on here with Nats. I don't know, NATS, I'm just saying, you know, so they're not investing in that, so they're not making contributions.
So Cincinnati is sitting there saying, well, you know, we, we've done all the investment. Why, why should, why should other people get to use it without us profiting from it? Well, Ellen and I went through this learning curve around open source, you know, believing, oh, many eyes, many contributors.
The real, the reality of it is, in most open source project, there is one or just a handful, very small handful. There's six at most. Yeah.
Uh, or even that, it's two or three oftentimes, maybe even one. Um, and doesn't mean they're not good project. They're great.
They can be great projects and widely used, but it does, that's one of the risks that companies are realizing now in, in open source, part of the assessment is who are the people maintaining it? Are they active? What happens if they go Away through that time?
It falls, it falls apart. Yep. Exactly.
But that, that's what I'm getting. So, so I, I feel like it's obvious you have to invest in it anyway. You have to invest in creating the product.
If you're investing in creating the product and providing an open source, and you're the only one doing it, well, it's your business model to create this stuff in the first place. And it's your responsibility, whether it's proprietary to you or open source, it's still your responsibility to sell it, resell it, have a go to market model, have a marketing model, you know, all of that sort of thing. So my, my sense is that Cincinnati has, has fallen down in those areas there.
If there's no market for it at all, okay, then there's no market for it at all. Whether it was open source or not. If there is a market for it, you can profit thereby.
And this, the, I think one of the original ideas in open source was, we're gonna, it's gonna be open source software and we're gonna, we're gonna profit off of services. Well, but that'ss not really. So, no, but, But you know what, I'm, I'm somewhat of an expert on open source business models, right?
So first of all, there have been successful open source companies. Of course, everyone always points to Red Hat. But, but beyond that, in today's modern software ecosystem, there's a number of ways of, of having a successful open source business model.
Number one, and probably most popular is, is the open core where the, the core of the project, of the product is in fact open. It may not have enterprise features, bonus features, the good stuff. And those are freemium premium add-ons, right?
So you could pursue an open core model, and, and there are a lot of companies who have done that and made a lot of money. Very successful model. Secondly is with the advent of SaaS software, right?
Open source is, is not really known as being user friendly. You gotta set up your own server and everything else. A lot of open source companies are saying, Hey, you wanna take the the code and go, you know, do the binaries and set this up yourself.
Have at it good luck. You wanna just consume it as a service. You could use Jenkins as a service or this as a service, and that is open source software, but you're paying us to host it, maintain it, secure it, updated for you, and make sure everything's all good.
And there's a lot of companies who have done that with a SaaS model and, and have been very successful, the pure, Hey, I'm gonna let you consume the open source, but I'm going to give you support and training. That's a failed model, right? That does work.
And I would add, yeah, and I would add to the SaaS that it can be on-prem, it could be internal SaaS, it can even not be SaaS. It could be exposed through APIs managed. Yeah.
Well, yeah. Okay. Manage, yeah, manage wherever it is.
I agree with you, Alan. Um, but that makes you a lot more like a traditional vendor, traditional software, or traditional, uh, solution provider vendor. And I know what you are.
It's just a question of the price. Well, Alan, I gotta jump in with this. You know, one, one of the things we've learned about open source, you and I, I think probably are like minds about this.
I'm gonna quote the great philosopher, um, posthumously, George Michael, also a singer. You know, you gotta have faith. You gotta have faith.
There are, there are people who just believe in open source period and build companies with it. And guess what? The user community figures that out.
Those are the people we like. They really, truly believe it Seuss of the world. And there are people who, open source is a business model, and conditions change will take it or leave it.
And those are the ones that tend to have not the true genuineness about it, that people pretty much sniff out and tell, and just wait for the crippled version and open source and the real version. I gotta buy in an enterprise version or whatever. I'm not saying you can't do that, but I think most of the, most of the development community, uh, and even platform engineers and technical folks, you know, really the people who enjoy open source really believe in it.
And they wanna work with companies that also are believers. Gotta have faith. Thank you very much, Mitchell.
Wham, Ashley. And, and that's a, and that's another thing we can ask the Pope to pray for. Yes.
Okay. I, I didn't realize. Well, he guy says he tweets maybe he, he's into, you know, he's in open source too, maybe.
I don't know. You know how you have to close the show now? You gotta close it.
Wake me up before you go. Go. You may have to take the one of those guitars down off the wall and play if you want us to close it like that, my friend.
Next Time. Next time. Hey, we're gonna take a break here on Textron Gang.
Let's come back to our v uh, C block. It's vexing VMware. You're watching Textron Gang.
Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO Leadership. Register now for free.
Hey guys, we're back in. We're gonna revisit this whole adventure. That guy and I went on to visit Nutanix in DC this week.
And yesterday we talked about an alliance with Pure Storage, or actually last Friday. And now though, one of the things they were doing is touting themselves as an alternative to VMware. And we all know about the VMware licensing changes, and the, a lot of, uh, folks are upset about that.
Let's just leave it at that for the moment. But Nutanix was out touting that they have now, you know, got some customers moving to their platform that includes small little construction companies to folks like Toshiba. The question though is how viable is that option, really?
Because like, even in Nutanix's case, they'll admit that there isn't that many IT administrators that are trained on it. They don't have as big a channel ecosystem and services provider partners. And you need all these things to kind of make that migration work.
And so, guy, I'm love to get your take on it, but almost every conference I go to now, somebody wants to beat up on VMware, and I'm like, okay, well, that's just legitimate competition, but I can't get my finger around are these, you know, one-off examples of somebody doing something, or is this the start of a trend where we are gonna see these major migrations? I think it's probably a trend. I think so.
So first of all, can I ask this whole panel a question? Why did Broadcom buy VMware For, for market share Money? I can't F That.
I mean, I think that that Broadcom has been tied up in the VMware ecosystem for a very long time, certainly before NSX because of the tight connections between VMware and the infrastructure. And Broadcom, of course, especially for switching, um, the backbone of these virtualized environments. Uh, they've profited very much by that.
But I, I've still, I personally, I still don't get it. There are a lot of explanations out there, um, market share being one of them, and I don't fully understand that. How are they leveraging VMware, um, to gain market share elsewhere, Or, yeah, no, I, I think Broadcom's broad, and we, we saw this, you know, when Broadcom bought ca ca had amassed an amazing DevOps portfolio.
One of the best out there Broadcom's model, as best as I can tell, is they already have 499 of the global, of the Fortune 500. They got 1,998 of the global 2000 and, and so forth. They're not necessarily looking for new customers.
They're looking to sell more stuff to their existing customers. They look at VMware and say, what percentage of the global 2000 and Fortune 500 of VMware customers? Very similar.
So that makes sense with these moves that, that they've made from the beginning. Thank you, Alan. Uh, there's certainly a favoring a reaving to the enterprise for the whole VMware portfolio.
Uh, and, uh, to be, you know, uh, to be honest, uh, my impression from last week at the Nutanix conference is that Nutanix in general is, is a lot more of, let's say, an intuitive operator, user friendly sort of approach to virtualization. Their core, of course, was storage, virtualization, hyper conversion infrastructure. But in the last four years, they have quite aggressively expanded outside of that into compute into containers.
Mitch, you, you, you wanted to add to this? Go Ahead and finish, but I got something to say about this. Go ahead.
Yeah. Okay. So, so they are becoming, uh, more complete virtualization and frankly abstraction platform, if you count containers into it, I, um, a variation of what Alan said, I think you can, you can look at why do they buy 'em by looking at the actions that they took.
Broadcom is the new ca ca was really a roll up, getting more and more products. They've been that from almost the beginning. And Broadcom has taken that very similar kind of tact.
And VMware is a captive market. It's as much as we talk about moving off of VMware, it is difficult. That is not, that was not for the VMware.
Ah, but I have news for you there, Mitch. No, no. Everyone, everyone claims they're making it easy.
And Nutanix's not the only one trying to nibble at the edges of v of this VMware thing. But here's an interesting fact. I found out companies that are moving off VMware are not necessarily moving off because the licensing three X was the primary driver.
They're moving off because they don't want to get, they want to move off lock-in, they want to go to the cloud. They want more options, and they don't get those options with VMware. And that's, that's a bigger reason to go into a Nutanix or any of the VMware bandits, Raiders, whatever.
AWS included, right? Is hey, we're offering you more freedom. And that's that.
So what George Michael too, Mitchell Freedom, I, I'm sure there's a wham quote we can find out. You know, wake up before you go, go. I think effectively though, a lot of those alternatives are not as conducive alternatives simply because of the nature of the applications being hosted.
I mean, Google put a one terabyte database into a container, I don't know, it's like five, six years ago now, as a proof of concept. If nothing else, it doesn't mean that you wanna run something stateful on A container. But a Ws they all have VMware replacements, guy.
They, we VMware I'm not saying that. I'm not saying they don't. I'm saying the operations of it are very different.
CloudOps very different from enterprise class enterprise. And that's a, that, that is partially a cultural, but just largely, uh, like to Mike's point that he's made several times and, and introduced us with, we're talking about an entire system of training certification, ena, partner enablement, uh, o original equipment manufacturer, like the, the, the pc the equipment, vendor enablement and all that sort of stuff. So there's your answer that What really does not translate.
So there's, that really doesn't, so, but Guide to your First Question. There's your answer. Why did Broadcom biome, I think you guys explained it really well.
I don't want to try and re-explain it. No, no, I think you just did. I think the other part, So I would po I would po I would po a theory here, though.
VMware may have miscalculated on how difficult it is to migrate. 'cause it is getting easier. It's not easy.
That's what I was, that's what I was saying. Yeah. It's Like, it'll, It'll, I can, there's nothing like a comet heading towards you for you to start thinking about, you know, uh, Ben a sending Ben Affleck and Bruce, I Was just gonna say Bruce, Bruce Into space.
Bruce Ben Affleck and Stephen Tyler's door to waiting for me. There We go, Bruce. So, so there's this motivation, there's this mo this, there's a very strong motivation that these shops never had before because they were, these were individuals who've invested their resumes in their career in that platform.
And all of a sudden they're like, whoa. But I, but I think part of this though, And, and, and, and I should say Nutanix is being extremely aggressive in sales. I've seen some of the programs that, fair enough, I'm just talking about Nutanix.
I've been briefed on it. They, they're really aggressive in because they, they then, they've been aggressive in engineering. They, they've, they've, they have invested heavily and intensely over the last 12 months in making those migrations Easier in many ways.
So we do a series of, of webinars with AWS channel partners, and I, I personally hosted three or four of them where the whole gist of the webinar was here's how you move off VMware to AWS You've done them too, Mitch. Everyone is trying to get at it. But here's the other thing.
VMware is not a stationary target. While Broadcom may be, you know, jacking up licensing, they're also honing VMware to be a better solution for those people who want what VMware has. And I think Guy and Mike both mentioned it, if you are already invested into that system, into that ecosystem In Tanz, it's not like you're on some ancient technology that's wasting away, they're maintaining it.
And the, and the inertia around that is huge, just around the psychology of it. I mean, people identify themselves as VMware administrators that, you know, they don't say I'm a generic administrator. They kind of attached themselves to VMware the same way DBAs used to attach themselves to Oracle.
And it took years to kind of Cisco Yeah. To see any, So, so, so let me, let me, let me explain then to people who probably don't need this explanation, what VMware really did, or I should say what Broadcom really did. It's not the changes in licensing, it's not any of that other sort of stuff.
The effect of what they did a year plus ago was to p**s people off, to p**s people off by making big changes that, that actually looked a lot worse in some ways than they were. But also with a restructuring with you. Like VMware had so many pet projects and they were pet to their buyers and their customers.
So I, to me, that's what, that's what the industry is reacting to and smarting from. It's, it's, it's, again, I, we always keep coming back to culture. They p**s them off and they are, they are.
And they p****d partners off too. They made every single partner real Thought. I, I think that was a a a, uh, they didn't do that blindly.
It was a calculated move. You know, the old saying, better to be p****d off than p****d on. And they, you know, they made a decision.
What percentage of that business would they be willing to lose by tripling the license and honing in on their, on the customer base that they want. You know what, we could sit here and speculate, but, but who's the Broadcom? CEO, Mitch, what's his name?
H ha Hoan Ha hoan hoan Htan. And, and, and I, he's, no, I really appreciate what you're, I really Well that's, I really appreciate what you, what you're saying, Alan. 'cause last week I was saying to Mike, when I don't understand what one of these folks does, I always know that there's something I'm miss, or well, there's almost always something I'm missing that I'm not seeing.
And you're helping to explain that because it, it has come off to me very like, off and, and, and, but I know that, that Hakan and the, the leaders around him and that organization are super smart, very strategic. Get, I'm sure they had it figured, figured out to the fourth decimal point. Maybe not to the prime number.
Yeah. Anyway, so you're saying, what you're saying guys, is you don't wanna miss the thing, right? Exactly.
Arm the peanut, the peanut gallery record company. Alright, that's it. I'm gonna do some studying before the next Game.
Oh my. And you're gonna hear From me, Mitch, gonna eighties pop music for 500? Alex, I'm, I'm gonna be trolling the Barry Manalow catalog.
That's what I'm gonna look at. Guy will take wham for 200. Alright.
Um, remember to answer in the form of a question, guys. We gotta wrap it up. We gotta wrap it up.
For those of you traveling safe travels. For those of you out there, stay tuned. We've got, we got text on TV coming at you right after this, so stay tuned for that.
Also, a quick reminder, if you're catching this, you can now watch us on our OTT channel where we're being updated every day. You could get OTT on Apple devices, Android devices, Roku, Amazon Fire, and Apple tv, text, drunk tv. Check it out.
Until next, until tomorrow, I'm Alan Shimel. We're out. Hey, everyone, welcome back here to another Techstrong TV interview.
My next guest, I'm pleased to introduce you to her is Vagi Koani VA Koani. I hope I got that right. Vagi, welcome to Text Drunk tv.
It's great to have you on here. Hey, Alan. Um, uh, great to be here.
Uh, thank you for inviting me for the, uh, discussion. Absolutely. So, Vay, you are the president of Enterprise Services and Train AI in RWS.
First of all, let's start with RWS. A lot of people in our audience may not know RWS tell us. Absolutely.
Um, RWS is a global company, and we are a leading provider of, uh, technology enabled language content and intellectual property services. Um, uh, for the past 20 years or so, we have been building our own AI solutions as well as helping a lot of our customers explore, build and use, um, multilingual AI applications. So essentially we are a tech enabled language organization, and, uh, we, we have been doing AI for long and helping our customers, um, um, unlock global understanding.
In fact, that is our, um, purpose, um, as an organization. Very cool. What's the website, by the way?
com. Great. All right.
So train ai. ai. That is AI agent ai.
Why don't we start off with what exactly is train ai? Absolutely. Um, train AI is one of the newest businesses that we are building within RWS, um, essentially to help, um, uh, support AI builders.
Um, so what we do in train AI practice is to, um, um, uh, one, um, obviously train the data, uh, which is required to build ai. So we have multiple service offerings that we, uh, uh, provide to our customers, which involves, uh, data collection, data annotation, as well as like validation of data. With advent of gen ai, there's a lot of services that we offer in terms of, uh, validation of, uh, content, which is coming out of, uh, um, you know, LMS and Gen ai, as well as, uh, test of, um, we can launch an application.
So we test for vulnerability. We test for hallucinations in the data. So, uh, to summarize in a, a core sense, the services that we provide helps build AI applications and essentially put out quality output.
So all the work that's done and prepping the data, uh, is what we offer as a part of our, uh, train services. Excellent. I love it.
Now, you guys recently did a, uh, a study with some benchmarks on this new Trane, A-I-L-L-M, synthetic data generation. And, uh, well, I don't know more about it than that. Why don't you tell, tell us what, you know, what was this about and maybe, maybe what some of the findings were?
Absolutely, absolutely. So we decided to run a very comprehensive, um, study to benchmark some of the LMS and their behavior to data. Uh, so there were two, uh, objectives that we had in mind when we started with the study.
Uh, we realized that, um, uh, the leading LLM developers, which includes OpenAI, Google, and, and the likes, um, are training a lot of their l LMS on the public information. And of course, to fine tune the models to specific domains or specific, uh, use cases, they need to rely on synthetic data, which essentially is generated by L lms. So one of the objectives for us was to, uh, see, hey, can we generate synthetic data using the LLMs?
And as a part of the study, we also wanted to benchmark and, for example, uh, qualify, um, uh, the LMS on, um, hey, uh, how are they, uh, performing in terms of reliability, in terms of their quality scores, in terms of their natural language, um, uh, quality, et cetera. So, so the goal was to generate synthetic data using popular L lms as well as to benchmark, uh, the LMS in terms of various parameters. So that was the purpose of the study.
And, um, um, uh, let me explain a bit in terms of like how we designed it and what exactly we ended up doing. Um, so we decided to test around nine popular l LMS for the study, which included, uh, GPT-4, Gemini Pro, Mistral, Lama, Jamba, and cla. So there's a bunch of them that we, uh, picked up, in fact, the top performing LMS in the market.
Uh, we decided to test out, um, around six task sequences, which includes sentence generation. So again, that was put into like simple, very domain specific entity rich conversations that you would have with the LLM. Uh, we also looked at like, um, uh, text normalization, translation, et cetera.
So it, it was a sequence of tasks that we wanted to test out and, uh, benchmark the study. Again, we picked out eight different languages to run the study, which, um, included the popular languages like, uh, English and French, and also, uh, some complex languages like Tamil, um, Kenya, Wanda, which is an African language, Tagalog, uh, simplified Chinese, et cetera. So it was a set of, uh, a different languages that we used.
And then, um, we wanted to evaluate these, um, outputs from LLN. So we decided to pick, um, expert linguists per language, uh, who would be rating the study on grammar naturalness, um, uh, kind of compliance, um, of the instructions and variability of code put that as generated. So that was the, uh, core, um, uh, study design principles that we followed.
And, uh, we, um, ended up, um, uh, kind of, um, um, testing out multiple performance dimensions, um, which included language proficiency, obviously, to test out, like how a language, um, like an English and, uh, French performs versus a more complex language, um, like a Tamil or, um, a Tagalog, right? Um, we looked at, um, how do these lms, um, um, follow instruction adherence in terms of like generation of sentences. Obviously we were talking about synthetic data generation.
So we gave instructions and we looked at like, what kind of, um, uh, inter instruction adherences followed by these lms, how many words are, uh, created, uh, per sentence, for example. So that was another dimension. We also tested out creativity, which is like output variability.
Is it just a textbook, uh, reputation of some data, or based on our prompting it, the LS are capable of generating something which is more conversational, more prone to, um, uh, human output. Um, another key parameter was speed. So which LLM performed, uh, fast compared to, um, the, the others.
And also there was a cost aspect, right? Uh, in, um, uh, in technical terms we, uh, call it as like tokenized efficiency, how fast, uh, and, um, how many tokens are used in this particular, um, uh, study itself. So these were like around five dimensions.
We tested out, uh, on all these nine ls that we picked up. Um, so we had some interesting, um, uh, findings from, um, uh, the study itself, right? Um, for example, we found, um, uh, strengths and weaknesses on almost all of these l lms, um, uh, on these five dimensions.
Uh, for example, uh, Claude Sonnet performed very well on most languages, uh, kind of like best instruction compliance, right? However, it took up a lot of, um, tokens, uh, to generate this particular data, especially in some languages like, uh, Tamil. And it was also slow.
Um, another example would be, um, Gemini Pro, which was like very creative when, uh, strong and, um, uh, languages like a Polish or Chinese tokenization, but actually flame failed in a language like Tamil. Um, Lama for example, performed, uh, fairly well on some of the languages, but was extremely, uh, slow. Um, mytral, which is like a French company, obviously performed very well on the French language with a decent speed, but did not work well on the other languages.
So it was kind of like a combination of strengths and weaknesses that we found on all of these, um, l lms. And, um, obviously one performed well versus the another, right? Um, some of the challenges, um, uh, uh, I would like to call out this, see, this is like kind of like a very fixed scope study.
So we cannot, uh, say that, hey, uh, this can be taken and applied to another a hundred, uh, languages per se. So it, it was, uh, a limited scope of like, um, um, nine different languages. Of course, we had indicated references in terms of complexity and things.
Um, so that's a limitation I would like to call out. Sure. And also, the human way, things introduce objectivity.
So it's more about like, Hey, how a human thinks versus a, um, machine or like, um, uh, system things, right? Um, so those are things. And, uh, if, if you have to, um, uh, ask me about a final takeaway, uh, our finding is of course, like not one LLM is like a one size fits all solution, depending on, uh, language needs or like specific use case requirements.
Obviously we have ranked, um, uh, the performance of each of these, um, uh, language models, and we could pick and choose them based on like what use cases we are trying to implement. So that's, that's an, um, uh, final takeaway if I have to summarize it. That was fantastic.
So, of course, you know, we don't have charts, we don't have graphs in front of us. People are listening to you and they're trying to maybe take notes, but it, I'm assuming the study report is available on the RWS website? That's correct.
Um, Holland, um, so we have two versions of the report. There is an exec version, which is kind of a short summary of the study itself, which is on the train eye site on the website. And, uh, we also have a comprehensive report, which is like a hundred plus pages in terms of like details and how exactly it was implemented, prompts, which is more for like the developers, technology folks.
So both the versions are available if anybody's interested in that, you know, exploring further, You know, in today's world, everyone wants the exact summary, but there are people out there who do like to get into the, the guts of it. com, should they, is it right off that first page? Is there something else?
Um, there is a train AI section on the train AI section. They could find it, or I could even provide a link, right? So, so we have, uh, yeah, If you could maybe we'll put the link in when this airs.
We'll put it in the notes. com, go to the train AI section, and within the train AI section, you will find a link to this, uh, benchmark study. Yep.
Fantastic. Masaki, thank you for coming on and telling us about this. Appreciate it.
Um, continued success. Keep, you know, we, we are, we, we've been, you know, AI has taken over our thoughts for the last two, two and a half years, but it's important to remember, we're just at the beginning of the beginning here, right? We're not even at the end of the beginning.
Um, so I'm sure as things, it's fluid, as things move forward, we'll hear more and find out and learn more. Keep doing what you're doing. Thanks for being on Techstrong tv.
Thank you, Alan. Thank you for the opportunity. And, um, being a technologist, being, um, um, um, AI expert, I do believe that, uh, there's a lot more to come and, uh, exciting times, Ly, it's a great time.
It's a great time to be in this. Yeah. All righty.
We're gonna take a break here on Techstrong tv. We're gonna be back with more coverage in just a moment. Welcome back to Text on tv.
I'm Lisa Martin, live from RSAC at Moscone West in San Francisco. We're gonna be talking all things security all the way through Thursday. Some great content we've already filmed.
Hopefully you've been watching more great content coming your way. My next guest is Naomi Buckwalter. She's the Senior Director of product Security at Contrast Security.
Naomi, it's great to have you on Textron. Hi. It's good to be Here.
Thank you for joining me. I'm So excited. How are you today?
I'm excellent. Awesome. My feet don't hurt yet.
That's day one. That's why I'm wearing heels. And I hope that is true.
True for the rest of it. I'm Me too. Fantastic.
That's one thing about conferences. You can guarantee a ton of steps and sore feet And no lines in the women's room. That's true.
Yeah, that is true. That's, that's one plus for us girls. So I love the tagline that contrast security, you can't stop what you can't see.
Tell the audience a little bit about contrast security. What is it that you guys are solving for customers? Oh, interesting.
Well, if I could give you an elevator pitch. Yes. We do application security in production.
That's the easiest way I can explain it. I love that. Right?
It's so easy to understand. Yeah. Well, if you think about it, we have other things in security production, things like we have our CrowdStrike that's running in production boxes.
Right? Okay. Like, we have different agents that run in production.
If you think about the vendor space, there's not a ton of application security happening in production, in runtime. A lot of it's before the runtime happens. So you've got your static scans, your SCAs, all the scans that happen in QA and Dev, and all the things that aren't actually production.
Yeah. And you have to wonder why it's, it's kind of weird. It's weird.
Yeah. Well, you were saying, you know, that doing AppSec in production isn't crazy. It's, it's smart's.
So smart. Why aren't more folks Wait, Did you say that or did I say that? I Got that from, oh, Okay.
You so smart. You're smart. Actually.
It's smart because, but why aren't folks doing that? Because it's where behavior happens. It's where the users are, it's where the attacks are.
Why aren't we doing more security where the bad stuff is happening? Right. Why do we assume we're testing for all the cases prior to releasing the thing in production?
Yeah. Well, I can tell you why. I know it's smart.
We just said it. You said it. But I think it's because people are scared of doing AppSec in production.
I think just tech, in the past we've had downtime is an issue. 999, whatever. Right?
To five nine. Thank you. And I think it's put us back a lot.
A lot. So if you think about some of the bigger breaches in the past, it really comes down to you probably just had this old server running with an unpatched thing for the longest time, and you were afraid of taking it offline off production. Right.
Just to fix it and then put it back up. Yeah. Because your business is like, no, we need all the uptime, we need all the revenue.
And it, and it becomes this problem because you don't have the protections that you actually need in production. Yeah. Well, It's a double-edged sword, and it's, it's like nobody wants to be the next headline for a breach.
So it makes sense. Right? I know.
I mean, the brand reputation, the churn that happens, nobody wants to be that. I mean, in these, in this day and age, security attacks aren't, is it gonna happen to us? It's when, oh, it's Happening now.
It's how often it's happen, happening now it's what is the cost? It's gonna cost my business. Right.
Right. So that alone, you think would, would make enough sense for them to put apps like in production Production. But I didn't even get to the biggest part.
It's because we don't have the insight that we need in production in our applications. We are really good as an industry of getting our network traffic understood. All the things that are happening on our hosts.
Understood. We know all the things that are going on because we have observation, we have sensors in those areas. Yeah.
What we don't have are those same sensors happening in our applications at Runtime in production. And now we're trying to say, as a company, I think it's time, it's okay to do AppSec in production. It's okay guys.
Like I almost feel like here at RSA would be our, like our unveiling. Yeah. Is that an, is that a word?
Yeah. Or unveiling, like our unboxing for YouTubers. Yeah.
Yeah. So it would be our way of saying to the community, like, it's time shift left probably has failed. Yeah.
Well, how much of what you're doing at Contrast is really education and making these folks aware that it's about, it's time. And this is why that old playbook mm-hmm. Has to be thrown out because nobody wants to the next Headline.
Absolutely. And and it's, it's a little like pulling teeth. Yeah.
If we had like an interpretive dance, maybe people would probably understand it more because it's, sometimes they're like, what are you talking about? Really? I had a dinner yesterday with somebody at a different company, someone who does static scanning, and it's like when I told him we should do AppSec in production, it's like, I stabbed his child.
Like his reaction to that, just like you could just tell his face. I was like, I'm sorry. Do I need to apologize right now?
Yeah. Like he was just so insulted the fact that even said that because it's so ingrained, it's cultural in us. Right.
So It's behavioral. Exactly. And that's Why Hard to change.
Why, but why. You're right. Our critical thinking turns off whenever we are thrown another framework.
Yeah. Or another way of doing something. Oh, and everyone does it this way.
Think of the thousands of other people here. So I'm gonna follow that line That you just Absolutely. Yep.
It's a bias that is not well understood by me, just because I could see the issues. Yeah. And most of us in AppSec actually do.
Yeah. And here's another problem is security. People traditionally don't have the best grasp of applications anyway.
Okay. So what they do is, or what we do is we kind of just say, Hey, we're gonna let the developers take care of it. We're gonna do our scans, we're gonna give them the issues, and then they're just gonna magically fix it.
That's not what the developers wanna do. Trust me. They wanna build stuff fast.
Yes. They wanna make money. They wanna go home and build cool s**t.
At the end of the day, I am sorry. They build cool s**t. Yep.
And then call it day. They see security people and they always have as a gate. Yeah.
A gate As a detractor to what they're trying to do as a No, you can't do it. Exactly. Yeah.
So what we are now saying is maybe that approach has failed us, because think of all the issues that are still having the OAS top 10 hasn't changed in like two decades. Right. How embarrassing.
For us, now we're saying application security can be done without the developers. We don't need them anymore. Okay.
Yeah. And I know that sounds really like, who heck are you, Karen? Yeah, yeah, yeah.
But we haven't given this a shot enough to say that Maybe it won't work. Maybe it will. Yeah.
Why not? Right? So you're in effect enabling the optimal developer experience.
'cause you're pulling this out of their, that's another way of hands. And the AppSec folks can take the responsibility on in production. Amazing.
Do you have a newsletter? I wanna sign up for your newsletter. That was really good.
Yes, you do. Yeah, So, so where are you talking? Who are you selling to?
Is it the developers? Is it the security folks? Is it both?
Is it the application owners? Oh my gosh. Well, everyone and anyone who will write a check.
But I will say we are targeting a new audience and it's our SOC people, our security operations folks. Okay. Yeah.
So what we're trying to sell them is more insight into the applications that are on their networks. Like all the applications and hosts that are on the machines that you care about, run processes and things and accept traffic and do stuff with that traffic in your host that you should really know about. Right.
So we're giving them observations, more data, more insight into their application layer, into their APIs that they don't already have. Right. And I think our soc, what we're hearing from the fields is that, wow, this is great.
Like before, it was just another network packet. Like, I don't know what this is doing now. It's, wow.
It's not only do I know where this packet is going, what route is hitting, what that route is doing, what it's executing in the host, or what data point it's hitting on the backend. Right. Like now that we have all that insight, we can do something about it.
If it's an application attack, we can block it because Contrast does that really well. Yeah. If it's a vulnerability that is out there, maybe we could tell the developers how to fix it.
And we do that too. Not only do we block the The attack, we can tell you where the vulnerability is. We can patch it.
Right. Like we have ai, how to fix, like we have all these cool tools that can just tell you how to fix it. Yeah.
It's really cool. Well, That, that application detection and response technologies, observability mm-hmm. Are game changing for organizations.
Yes. It's like the tagline that I, you can't stop what you can't see. You need to, they need to have that visibility.
Yeah, absolutely. But also in a sense, getting outta the way of the developers. Letting them have the optimal developer experience that they want.
Yes. That they expect. Yes.
But providing that visibility so the blinders are off. Absolutely. And you're letting them do their job better.
Yes. And you're doing your job better too, as security people. Yeah.
Security people can do application security. I know it's sometimes hard because you have to keep up with your technology. Yeah.
But once we do, we can show them we're on the same team. Right. And then now you're building relationships.
Yes. Now you're building culture on your teams. And trust.
And trust. And that is, is a hundred percent Yeah. What you need when you're working with developers.
Like Yep. I had conversations, we were like, why are we doing it with you guys? We can ruin your life if we want to.
Like, that is an adversarial relationship. Wow. Right.
This is not a person that I worked with. Yeah. I was just talking to, they're like, we can ruin security people's lives if we want to.
Like, why are they sending to us? Right. Wow.
Power. Right. Wow.
What's your favorite customer story of contrast that you said you think this just perfectly shines a spotlight on what we do well and why we're doing it? Well, It's funny 'cause I'm a security practitioner. I'm my favorite customer.
I actually use contrast every single day. Wouldn't Awesome. Drinking your own Champagne and I wouldn't Thank you.
Oh, not the dog food thing. No, no champagne. Want.
I like the champagne. I elevated it. Thank you.
It's so much better. Well, so I'm a secure, I'm a security practitioner. I would not be working for a security vendor if I did not deeply believe in our products.
Yeah. I am not even saying that lightly. Like I understand how cringe it is to be here.
I'm sorry. RSAI love you. But it is cringe.
And I will say it's just like LinkedIn. It's like, why are you so cringe? Why do you have to do this?
Cringe. It's security vendors doing too much and it's not actually helping do security. So me as a security practitioner really appreciates a tool like contrast.
'cause it makes my job so much easier. I don't have to do a scan and be like, here's 500, um, 500 vulnerabilities. That's a static and I haven't even validated each one.
Good luck with that. Developers. It's like I can give our developers actual vulnerabilities, actual vulnerable routes, things that have been exercised in our applications, which means endpoints that have been hit Yeah.
In production because we know this is a route that has been used and here's a vulnerability, here's an attack that happened, and then we could do something about it immediately. I don't have to wait for the patch. Right.
I can do something in our tool. Contrast can be like, okay, we're gonna block this for now and then gives us some time to patch on the developer side. Yeah.
And think about Log for Shell. It was the same way. Yeah.
We blocked log for Shell out of the box before anyone even knew Log for Shell was a thing. Wow. And now it buys the developer's time.
Yeah. Right. Because you're like, yeah, you're using old versions of Log for J that are vulnerable to log for Shell.
Yeah. Go ahead and fix this thing. Right.
And by the way, we have contrast on the other side acting as that last gate. Yeah. Thank God we have them.
You know, you Should be a developer's. BFF. I already am Lisa, I dunno what you're Talking about.
Of course. You're, Naomi, it's been such a pleasure having you on text, on tv. Thank you for really explaining what you guys are doing so well.
Why apps suck in production is smart. We appreciate your insights and your candor as well. Appreciate that.
For Naomi Buckwalter, I'm Lisa Martin. You're watching Text on TV live from RSAC. We'll join you again after a lunch break with our next guest.
So stick around. Hey everybody. Welcome.
Welcome back to RSAC, the techron coverage from Techstrong tv. I'm Mitch Ashley, uh, Futurum leading the analyst practice for application development, DevOps, application security, all kinds of good stuff. I'm joined by what I would call a good friend.
Brian and I have gotten to know each other, uh, for a long time, talking usually at these kind of events. Yeah. Most of the time.
We're about half the time we're on camera. It seems like We just did this, didn't we? We did.
I think. Well, we should just pick off from wherever we were last time. So Brian Fox, introduce yourself.
Tell us you know, your background and hi Some Type. Sure. I'm, uh, Brian Fox, co-founder and CTO at Sonotype.
Um, I'm also on the open SSF governing board and the Enos governing board and, uh, Singapore Monetary Authority Cyber Board where I was last week, uh, talking about a lot of this stuff. So yeah, that's, that's me. Long background and open source.
You certainly do. And distinguished and a lot of contributions. Thank you.
Which definitely appreciate it. Um, yeah. Um, lots of things we could talk about.
You know, I'll hold off the AI word if we want to for the moment, but, you know, one of, one of my senses in kind of knowing that we've gone through this before, right? Adoption of the cloud, adoption of rolling out things in Kubernete and uh, in Covid. Um, it's always kind of what, and what do we do about security survey after the fact?
And hopefully we're not doing that again, but it kind of feels like in a way we are, is is security sort of the, uh, secondary thing. It's not off the radar, but it's let's vibe code, let's create agents, let's do all these things and okay, how are we gonna secure it again? Um, JP Morgan Chase CISO issued a letter saying, Hey, the industry needs to step up and do more about security.
If you were gonna write that or you were gonna give that talk, what do you think we need to be doing? Yeah. I mean, I, I feel like I could have written the same letter.
I feel like it's the same thing. I've, that was my First Reaction time. Yeah.
Um, you know, I've kind of gone through this, uh, this cyclical thing, you know, like I, I, I felt like 15 years ago the problem was awareness. If we only educated people, they would do better. And that's true to a point.
But I think over, over the last, you know, like I said, 15 years or so, the industry has, has gotten better, but not better enough as we've seen with all of the high profile attacks. You know, SolarWinds, log four J, you know, all the malicious attacks that we're seeing these days. Um, you know, and so in response we saw, um, you know, regulators worldwide stepping in and trying to put their thumb on the scale.
And, you know, I've kind of been a champion of that over the last handful of years and trying to, to, to work to massage that and make sure that those, those policies are effective and not punitive. Um, you know, we we're potentially seeing a, a backing away from that. Um, you know, that that momentum, which is a little frustrating, at least here on the US side, you know, Europe, India, Singapore, they're still pushing hard on that.
Um, and I, and I think that that's good. Um, you know, and so, you know, the open letter from JPMC is sort of, you know, calling on the industry to do better. Um, you know, my response to that is like, that's great also, um, you know, the industry needs to be able to kind of put their money where their mouth is, you know, the, the, the vendors to these large banks, we'll do better if the banks demand it.
Mm-hmm. And so it's, you know, asking them to do better. I feel like that's what we've been trying to do forever.
You know, so there's two ways you can move that needle. The regulators can force it. The, the large consumers, banks in this instance can also force it.
You know, that was sort of the process that the US government was taking about sort of mandating SBOs, um, mandating, uh, attestations, things like that. If these large software acquirers, non-government ones can do it too. If they start demanding the same things, I think it will have the same effect.
But they have to band together and do it, and they have to be consistent about it. Yeah. I almost wonder in part if that letter might've been issued because of the change in direction with cisa.
You know, we want you to focus on securing, you know, a national infrastructure less, I would describe it as less taking a leadership role. I won't put you in a position, it's describing it, but it, it's almost like, okay, now we have to step up in a different way. The, the large consumers of technology is certainly one approach.
Mm-hmm. To that. Um, any, any other thoughts of ways we might collaborate, work together to strengthen security as a community?
I think I, I think it's those two things that I said. Either the, the, the government steps in to force it, which can often be heavy handed. Uh, or, or, you know, ultimately consumers have to demand it.
And, and in this instance, I'm not talking about end user consumers. Mm-hmm. I'm talking about, you know, the, the large enterprises that are the consumers of software.
If, if they need to demand it as well, only then will the economics force businesses to prioritize these things in the right way. Uh, you know, I, you and I have spoken about soft liability reform and things like that, you know, and, and that's part of it, because until we can rebalance the, the economics so that, uh, losing data costs more than just buying people, uh, their 10th subscription to credit monitoring, until those economics are, are balanced, that we won't see the behaviors change. Right.
And so there's many ways to balance them, like, like we've talked about. Mm-hmm. So I think, I think we need to see that we're not seeing it enough.
And certainly, you know, with the, the, the land grab gold rush, whatever metaphor you want around ai, you know, it's, uh, like, like you touched on in the beginning is kind of, we're seeing a backslide, I think, in that too. Yeah. I remember sense that of like, you know, we need to get ahead, you know, every day we're, we're falling behind faster with AI because of the pace that it, it's moving.
Yeah. So, so speaking of ai, someone mentioned at a, at a talk that I was at, uh, well, we won't do anything about security and AI until the next, for the first big event happens, sort of the, the target data breach, the log four j the, you could pick out whatever kind of milestone occurrence that got everybody's attention. You could also argue, well, that could happen very much faster if with the pace that AI is moving and how much people are doing vibe coding, or agents are using AI in their tools, but not securing it properly.
Do you, you follow that too? Is, are we kind of desensitized to the next big event gonna cause anything to change? There's definitely that element.
I mean, I think, um, you know, the, the, the, the desire to keep up in the race for AI is causing people to grab the latest things, you know, without vetting them. Right? And so it's like, oh, there's a new model out on hugging faces, let me grab it and, and give it a shot.
And so these are the exact behaviors that lead to dropping of the guard that, that the malicious actors look for, right? So there's already been cases of, of, uh, copies of models that are put out there that do nefarious things. Now, the, the, the danger with the AI is that, you know, you tend to want to feed it information.
So it's a little bit different than just a piece of software that you're running that may or may not have access to the Role of data in it is even, Yeah. Right. May, may or may not have access to lots, lots of your data depending on what you're doing.
But that's like, that's the main point of you of the ai. People want to grab these models and kind of feed it all of their data. Well, if that's an untrustworthy piece of software that's hoovering all that data and sending it somewhere, it's even more dangerous than, than what we've seen.
And so we have this interesting collision of people are, you know, dropping their guard trying to go fast, trying to new the, use the new and novel thing and not really thinking through all the implications. Mm-hmm. You know, I, one of the things I've been thinking about too, is one of the differences with AI is since it's, it's code driven, but it's driven by prompt and, and so there's so many more ways of injecting prompts or AI changing its own prompts.
Yeah. I mean, you've got this whole vector in there that, um, can be interjected not just by users, but by code and also other AI systems. So in some ways, we almost need better internal security within AI systems, not just good guardrails, but what happens when AI is generating Yeah.
New and novel things, if You will. I mean, the, the power of the AI systems comes from the fact that they're not exactly deterministic. Mm-hmm.
Right? That's why they're so useful. Um, they, they, they can approximate novel thought, right?
Hmm. Um, but that also makes it impossible to actually thoroughly test all of the things. So where does that leave you?
It leaves you in a world of having to depend upon trusting, trusting who provided it, trusting the data that went into it, trusting, you know, the, the tuning and the, and all of these things. Um, but we're still in a place where there's not a lot of visibility into that. This is a problem we have in open source.
It's why the massive rise of malicious open source is out there, because we don't know who the authors are, even on the popular software that is good, right. They're, they're somewhat anonymous people behind the scenes. And, and I think, you know, AI is gonna force us to rapidly reconcile that because you can't, you, you know, in theory you could take a piece of open source code, you could read it, scan it, do all the things, and get comfortable with the fact that I understand what this is.
There's nothing weird in here. But you can't do that with ai. You're talking, you know, petabytes of data that it's been trained on.
How do you know if that's been curated to have a specific bias or not? Right? How do you know what the model numbers have been tuned to?
Can you really prove it? Right? So it gets to a point where it's impossible to really inspect this.
And then, then you get back to, well, I just have to trust it. I have to trust the people that provided it and, and all these kinds of things. But we don't quite have that visibility mechanism yet.
So I think that's kind of push us in that direction pretty rapidly. Can You talk a little bit about maybe for Sonotype, as AI has risen, risen onto the scene, and I know you're very much overthinking in your approach to this. How has that changed your product strategy or thinking about AI and models and Security?
Yeah. Yeah. So early on, our customers started asking us, you know, how do we, how do you help us govern these things, right?
So we have a long history of helping organizations detect and govern the open source components that are going into their software. And so from that perspective, AI is just another, albeit large and hard to quantify component, but it is just another component at the end of the day. And so we're seeing a lot of the same patterns, uh, that we saw early days where we had talked to leaders and they'd say, we don't use open source.
And it's like, yes, but, uh, you downloaded a hundred thousand components from US last year. Um, you know, and so it's sort of a case of leaders say you shouldn't do a thing, and they assume that that's what's happening. And without the tools to validate and govern it, um, they can't know that they're wrong, but they're usually wrong.
Mm-hmm. And this is what we saw with open source. And so we added capabilities to our system to be able to detect, provide metadata around the models, you know, and it, and it goes beyond the traditional, you know, security quality and licensing that you see in open source.
But now we have to think about bias and, and, you know, other kinds of things, derivative models. And is the, is the, the data, you know, the software license might be one thing, but the data license might be a different thing. And, and these other types of aspects.
So we've had to expand the, uh, parameters of metadata that allow them to reason. But the most important thing is being able to discover the ai, right? And so we see a lot of people talking about AI usage, and there's sort of two different pieces to that.
There's what the tools are, so think co-pilot and other things that are helping you create code on the side. But then what we're seeing in what we're helping them manage is the developers are baking these models into the product, right? Just like another open source component.
And, and many leaders are focused on the first one and completely missing the second one. Mm-hmm. And so that's where we've been focused, um, you know, because our platform and everything else is already kind of designed to be able to manage that problem.
Mm-hmm. Excellent. Um, you know, someone said to me yesterday, the pivotal point in their career was when they sort of stopped pitching FUD to the CEO and had to start pitching.
And here's, here's the value to the business. Why, why this is important, not just important, but the benefits security brings to the business. If you're gonna help one of your colleagues or customers or friends with their pitch around software security, maybe including AI as well, what are some things you'd want to make sure key points you'd wanna make, help them make On their pitch about Pitch to fund, uh, software security projects?
Wow. I know. How much time do I have?
I, I saved the easy ones for you now. I do. I save the challenging ones.
'cause you're The guy to ask. Yeah. You know, I, I would think, um, you know, pitching them to make sure that they have the investment to be able to truly understand what's inside their software from all of the different dimensions.
Ai, like I explained, is, is like a whole new, uh, you know, uh, factor that with so many new dimensions. So what, what we see is so many organizations are struggling to deal with just being able to produce something simple like an SBO m for their existing open source. If you can't do that, you're not prepared for all of the malicious components.
You're not prepared for the AI components. So I think you need to be thinking about, about it holistically and not assuming that things are okay. Um, because oftentimes we're finding that they're not.
Um, and it's a, it's a case of just because you haven't found it doesn't mean it's not there. You know, if I'm from New England, we have radon in our basements, but if you don't have a detector for it, you wouldn't know it's colorless, odorless, tasteless. You have no idea.
Just because you you haven't tested for it doesn't mean it's not there. And that's kind of what we're seeing with, with certainly these AI models that are being baked into software. The developers know they're the ones that are doing it.
It's the leadership who's responsible for knowing They're somewhat unaware of these things. And, and that is not a good, good Situation. Yeah.
Ultimately, who's gonna get held accountable for it. Exactly. Right.
Right. Yeah. They're ones that responsible to know.
That's right. Yeah. So, la last topic, run out time.
We could go hours, you know. Um, what's, what's top of mind? What are the things you focus on focusing on for the next six months or so?
What kind of, what are you looking at? What are you researching, thinking about working on? I mean, of course, every, every conversation is like this one around AI and the intersections of it.
You know, there's still a lot going on, um, in Europe around, you know, providing the details behind the Cyber Resiliency Act and the product liability directives. You know, the, the community, um, is working pretty rapidly to try to define what those best practices are. You know, because the regulations say if you don't follow the best practices, you'll get fined.
But it didn't define what those are. We're in that process right now. Mm-hmm.
Um, you know, and, and a lot of that has to be, has to be done in the next six months. Right. So there's a lot of work going on, um, to, to, to focus on that.
Um, you know, we're seeing other, other countries following suit. You know, India recently released some of their regulations, similar things. So we're seeing a lot going on there.
And that's, that's keeping a lot of us in the, in the industry busy to help kind of make sure that the best practices are, uh, the right ones. Mm-hmm. So that the, the legislation is effective.
Well, good. Well, maybe even if the US is pulling back or redirecting what it's doing, international community is not stopping either. No, they're not.
And every, every, every significant company is a globe in, in software is a global company. So these regulations that apply in Europe are gonna drive action regardless of where people are headquartered. Right.
So I think that's at least some of the good news that we're going to see, you know, uh, we're gonna see that change no matter what. Good. Well, thank you.
Hey, keep up the good fight, man. Thank you. Alright.
Good to be talking here with Brian Fox. Thanks for tuning in. We have some more live interviews coming up here on Textron tv.
Coming to you from RSAC and Broadcast Alley. We'll see you in a minute. Hello and welcome to the AI Leadership Insights series.
I'm Amanda Ani, and with me today I have Albert Roux. He is the EVP of Product at Micro Blink. How are you doing today?
I'm doing great. Nice to see you, Amanda. Nice to speak with you.
So, uh, share a little bit about Micro Blink. What services are, do they provide? So, micro Blink is an AI powered, uh, company specializing in, uh, digital identity.
So we provide solutions to capture, uh, identity document, classifies them and verifies them, uh, remotely. And we have also an identity platform that enables us to verify not only documents, but also biometrics and conduct database checks for our customers. Alright.
So our topic of the day is how artificial intelligence is impacting the cruise industry. So can you share, um, from your experiences, what are some key use cases for AI to improve the cruise industry? Yeah, definitely.
Uh, actually, micro blink is, uh, uh, a company was a, a wide range of customers across different verticals, but particularly we well established in the hospitality and travel. Uh, so therefore we have a lot of customers, uh, who are actually, uh, cruise lines. So I think when we, we think about those type of customers, their main pain points is primarily the user experience.
So, onboarding a cruise ship, as you know, is always a little bit painful because you're dealing with thousands of people. Uh, the crucial lines have to actually, uh, verify your identity just like airlines do. But also there's additional, uh, regulations that applies to them because they also operate, uh, online cas.
So, but primarily I think for them is to ensure their guests have a optimal experience, especially during the onboarding time. So what does that mean? That means that they need to be able to verify, uh, their guests, um, identities, uh, in a most, or at least the least intrusive manner.
Uh, especially when they ask to provide, uh, your passport, your, uh, driver license or also identity documents and verify, uh, who you are, uh, including your biometrics or your face match. And then pair it also to their, um, sometimes some of those companies have, uh, uh, bracelets that enables you to access, uh, certain, uh, services or even, uh, private islands that they may operates, uh, into. So I think, uh, the main use case primarily is around onboarding, but also, uh, accessibility to certain services.
And third, obviously is, uh, compliance with regulations or K-Y-C-A-M-L because as knows a lot of people don't know this, they are actually a financial institution, so they are subject to the same regulation as banks. Hmm. Um, do you have any, uh, examples you can share where a cruise line or any kind of, um, company within the hospitality travel industry implemented AI and saw some immediate results?
Can you share kind of that return on investment that they experienced? Yeah, so absolutely. Uh, I think there, there's different ways you can actually verify, uh, someone's identity.
So you can do it of course, obviously when you arrive, uh, at the port and verify the identity via ki, right? So that's one way to do it. And even those chaos, they actually are powered by AI already because you capture information using, uh, uh, computer vision and OCR or optical, uh, uh, character recognition.
Uh, and we, we, I mean, essentially your skills capture an image of your identity document and have to extract that information to verify it. Uh, they also, uh, leverage biometrics now. So facial biometrics, those are, uh, purely, uh, ai, uh, machine learning models.
So in, in reality, they've been doing this for quite some time. And, uh, what they, they're trying to do, of course, is to optimize the time now that it takes to onboard, uh, uh, a customer. So they do it at different levels and at different touch points, uh, during the journey of their passengers.
So onboarding is of use is one, but also, uh, during the course even of the cruise, right? So let's say for example, you want to, um, disembark and visit the private islands, especially in the Caribbeans, uh, or anywhere else in the world, uh, they're going to, uh, have the need to verify, uh, not only your identity, but sometimes also your age, because you have also adults, uh, areas of the ship, but also of the island. So in reality, uh, AI is used at different, uh, stage, uh, from, uh, verification of identity, verification of your biometrics, and also even checking whether or not you're present on certain lists, right?
For example, uh, politically, uh, exposed person. So even though it seems like a simple, uh, data match, but is a little bit more complicated than this, uh, on the backend. So I, I, I think there's different ways, uh, this is done.
Uh, another way of you see is even prior, uh, prior to having you onboarding, onboarding the ship, is they, they want to optimize their, uh, app experience. So you see, everybody has a mobile phone these days. So even before boarding the ship is they can, uh, actually already accelerate your onboarding experience.
They will do it. So via, uh, the application, most, uh, major cruise ships now have, have an app that you can leverage to, uh, establish your identity, but also, uh, uh, purchase things, right? And, and the moment you purchase phones, there's the risk, uh, in their end to be, uh, comprised or verifying your credit card, verifying your, your transactions, uh, issuing, uh, maybe a digital key to opens the door of your, of your room.
Those all, uh, leverage, uh, essentially ai. Wonderful. So, uh, from your experience, where do companies experience challenge or roadblocks when they're implementing this new AI technology?
I think the biggest challenge is, uh, what we, uh, people don't realize is we have to do that globally. What does that mean? That means that you need to be very able to verify, uh, wide diversity of documents.
Uh, you need to do it for passenger from all around the world. So if you, I live in Florida, so I'm, I'm pretty familiar with the, the cruise industry. And it's not only Americans or Canadian boardings of cruise ship is Italy, Europeans, uh, people from South America, Africa, Asia.
So the, the number one challenge is you have a solution that, number one, is easy to integrate with their current systems, especially, uh, billing, for example, but also, um, able to handle, uh, any type of document, uh, globally. And sometimes we have some customer who operate in zones where there's no internet access, meaning you don't have access to cloud services. But what happens now, uh, if you don't have access to, uh, a server that you can access to verify someone's identity.
So, uh, that experience needs to be actually, uh, happening on device now. So that's where MyLink actually for k is we provide, uh, models, especially machine learning models or computer vision models that can operate, uh, entirely offline and, uh, on a, even a, uh, something as small as a mobile device. So I think that's another challenge that people don't understand, is when you travel, you don't have internet everywhere on the ocean.
So how do you, uh, uh, provide those services continuously during the, the journey of a, of, of a cruise? So those are, are really the major challenge that they face. AI is advancing quite rapidly.
So what do you see in the future of the travel industry and the cruise industry as it relates to ai? What are some other use cases that you envision? I think the main thing is, uh, to understand AI is a great thing, but also bring some, uh, also risk.
Uh, AI obviously, uh, can help you generic, fake documents or even, uh, potentially, uh, fake, uh, uh, carry parts, right? So the minute you start to have a presence online or, uh, the ability to verify someone, uh, uh, identity online, you also, uh, open the door for frauds. So, uh, who says that the person that you just onboarded on that cruise ship is actually that real person.
So you, you're going to have to leverage, uh, a combination of, uh, computer vision model for document verification, but also for the biometrics. So, uh, that is the part that the cruise ship, I think, needs to, need to worry about, because now those tools that trust use are much more advanced than before. That's one.
And then you see, you, you have going to have to deal with potential issues just like illegal immigration or, or, uh, uh, money laundering, all those issues. And, and, um, push, it could be the perfect, uh, opportunities to, for those people, uh, for the fosters to do that. On the other hand, uh, at the same time, uh, I think a huge benefit of ai, especially with the new, uh, what we call the, uh, LLMs, but essentially what the chat GPT of the world to not to name them, uh, enable, uh, also, um, those companies to have a better understanding of their customers.
So, uh, having maybe reducing the cost or something just simple as reducing the cost of personal owned ships, uh, that can give information to passengers. So, for example, I mentioned earlier where muscles of cruise ship have an application, uh, a mobile application that you can have on the phone. But, uh, imagine now that you can have an intelligent, uh, chat bot who can actually start to ask you questions.
So to get to know you better, provide better experience, tailored maybe an evening for you and your spouse to have dinner, uh, on a cruise and already pre-order maybe the meals that you like. So you can imagine the possibilities of an AI who knows everything about you and then can tailor a better travel experience for you. So I think this will be, uh, could be something that I'm sure the cruise, uh, cruise can, can look at.
I wonder if eventually we'll see AI robots, um, as service providers on cruise ships. Yeah, I think you, you can see that in some hotels already. I mean, they're not actually, uh, actual Android robot cf, but there is some in certain ca casinos around the world or even hotels, you can actually order food.
And then you have that little robot. We can bring users this. So I think this is going to be an evolution, a natural evolution of where we see, uh, AI going probably in terms of customer service experience.
I think that's going to be, that's gonna be a great one for passengers. And you can probably see what, uh, companies like Tesla are doing where they start to work on their own, uh, Androids. So apix, one of the primary application for this is of you c hospitality or vertical.
And I think that's going to be, um, that's gonna be great for, for customers. Well, if there was one key takeaway you could leave our audience with today, what would that be? I think, uh, in general, I think for ai, uh, is going to be a huge benefit in terms of, uh, experience for the end user.
When you're boarding a ship now, you, you won't have to suffer through long lines, potentially. You could have done all those things at home, and then all you have to do is to actually go to the ship and, uh, everything else will be taken care of you by an intelligent AI who knows, you know, your tastes and enhance your, your experience of all, and then also diminish the risks to you, right? You to have Craig Mo with you on, on those cruise ships.
So I think, uh, if I can leave, um, uh, the audience here with, uh, some, some wordies, I think it's going to be pretty exciting for everyone in, uh, in the cruise ship, uh, industry. Wonderful. Well, I love cruising, so I can't wait to see what's next.
Uh, we like to go every year, so. Alright, well thank you so much for coming on the show and sharing your insights with us today. Thank you, Amanda.
Appreciate the time And thank you to our audience. Stay tuned. There's more.
Hey everyone, it's Alan Shimel and we're back here live at the, uh, RSA conference covering Wednesday. We are live. You can see behind me the activities picked up a little.
I think some of the sessions are led out and there's a lot of people heading over to the West keynote stage. Magic Johnson is going to be on keying and about 45 minutes and, um, there's already lines forming and people streaming in. What does it say that Magic Johnson, he's not really known as a cybersecurity expert, draws a much bigger crowd than any of the cybersecurity people we have in keynotes.
But You, you could take a break from lot of cyber and AI talk tracks, Right? Yeah. And go see Naja.
Well, yesterday had Ron Howard, you know, uh, as well. So all interesting. Anyway, I want to introduce you to deepen Desai.
Deepen is the, uh, chief Security Officer at Zscaler, one of the great security companies out there. It's a great story. I was talking to DeepEnd, of course, the founder of Zscaler is Jay Choudry.
He's kind of a legendary guy in the cyber. When Jay got involved, we didn't call it cyber, it was the InfoSec space he's had success with. I think Zscaler might be his third big company, right?
He had two other Yeah. Really big companies. But deepen, you've been with Zscaler, what'd you say?
11 years? 11 Years, yeah. So You've been, you've, you've, you've seen this, I've seen the growth.
Yes. Absolutely. It's been an amazing thing.
Dein ZScaler's not a company that's not familiar, that's a double negative. Zscaler is a company that's very familiar to our audience, but maybe there are some people who don't know. Right?
So why don't we just get that outta the way, let 'em know who Zscaler is, what you guys do. Sure. So Zscaler is one of the largest cloud security company.
Uh, our motto is to provide Zscaler zero trust exchange. We're like a switchboard that connects entity A to N entity B in a secure fashion. And when it comes to anything that goes out to the internet, our goal is to make sure nothing bad comes in, nothing good leaks out.
And for connectivity to your internal application, we wanna make sure that we're doing it in a way that we're not, uh, we're, we're basically reducing the lateral propagation attacks. Absolutely. Look, I've always explained it to people that Zscaler was the first Network security tool built for the cloud natively.
So I don't mean cloud native and Kubernetes per se. I mean natively built and for a cloud environment where before Zscaler, we had that Moten castle sort of model, right? You had a big box that so stood in front of your, your land Yeah.
And everything ran through that box and we inspected it and we snorted it, and we, you know, firewall did and everything else. When Zscaler, we realized there wasn't that moat and castle anymore. We couldn't put that big box in front of everything, but we could look at the traffic as it came over the cloud network to the land or wan and inspect that traffic, whether it be in a sandbox or, or some other way before letting it go through.
And of course, the trick was to do it with almost no latency, right? Yeah. And that to me was the magic Yeah.
Of Zscaler. The way to think of it is as, as users started becoming hybrid, whether it's, uh, working from home, traveling or in office, applications started moving out from that castle that you were describing. Mm-hmm.
They're now in public cloud. They could be in data center or they could be in the corporate environment as well. Uh, with the newer technologies, like whether it's iot, ot, ai, now you need security that follows the users and the application.
You cannot have that castle and mode approach anymore where you're back hauling stuff and trying to do everything Just makes no sense. It's wasteful. It's doesn't bad Experience.
Yeah. Yeah. And you're not even able to apply security.
Agreed. Agreed. So, but you know, I'm giving you Zscaler 2010 or something like that, not Zscaler today.
Your job's to give a Zscaler today. Yes. So today, again, our, our primary mission is to make sure we enable organizations to adopt zero trust everywhere strategy.
And it is even more important now as we're starting to see AI driven threat landscape evolve, right? Um, uh, when you think about human adversaries, they use a certain set of playbooks. When you think about an AI adversaries, there's gonna be a lot of those unknown, unknown things that we will have to counter against, which is where if you have zero trust architecture implemented, you're essentially simplifying your network, shutting down the vectors or the attack paths that whether it's human adversary or AI driven attacks, you're basically able to protect against that.
Right? Absolutely. Um, you mentioned the AI word, checking my watch, we made it about three minutes mm-hmm.
Until we mentioned ai. Of course, AI is everywhere at this show. Not only at this show, though it's everywhere.
Yep. How is AI changing the game for Zscaler? Yes.
So, so look, as an, as an organization, we ourself, so I I'm the cso, uh, of the company, which means just like all the other CXOs out there, I do have a job of making sure we're securely enabling AI adoption in our organization. But being the cyber vendor as well, we are also implementing a lot of those learnings. And we've already done that, where the zero trust exchange allows organization to securely adopt ai.
So we're able to inspect traffic going to these AI applications like Chad, GPD Pro pilots. We're able to make sure that none of the sensitive data leaks out, uh, because we do TLS inspection over there as well. And then we are able to provide you a full visibility, uh, shadow AI is a reality.
Sure. You know, I was talking to a CSO yesterday, like every company has AI adoption going on, is just, whether you know about it or you don't know about it, that there is, uh, usage of ai, your employees are trying it out. So that's where Zscaler does help provide that visibility security controls to make sure there is no risk, um, of data exploitation.
Now you ask how is Zscaler using it as well? So we are absolutely integrating AI across that exchange because we strongly believe you need AI to fight ai. Right?
So this is where across the stages of the attack we have models implemented. We're also using generative AI capability to do neat things like predicting breach like scenarios because it's able to process large volume of data at scale. Um, Love it.
Um, you guys recently came out with a, a, a, uh, report share. Yes. So just last week we published our annual phishing report.
This is, uh, a report that comes out of our security research team threat labs. Uh, the team, uh, looked at 2024 findings, and this is where we were able to, uh, glean insights into type of attacks that are happening. Um, one of the interesting finding, and we are not surprised, is the overall volume of phishing attacks went down almost 20% globally.
Were apps Absolutely. Seeing a shift from volumetric attacks to more quality attacks. And AI is one of the reason because they're leveraging AI to craft very targeted email, bringing in context.
So let's say the threat actor is targeting organization A, they will look at what all things are going on for their organization at that time. Is there an appraisal cycle? Yes.
Then I will do an equity grant, spearfishing email. Is there a mergers and acquisition tag going on? Then I'll use that.
So they're able to bring in that current contract, They up the game And they're able to craft email, which is flawless. Doesn't sound like it was written by English as a second language. Exactly.
I know. So, so we're starting to see more and more of that. And then in the report we also call out other vectors like wishing where they're picking up the phone using clone voices.
Yes. Uh, we saw video Based clone voices, cloned vi I was just gonna say cloned video. Yes, exactly.
So we're, we're starting to see an uptake on that as well. And as we head into this year, uh, I wouldn't be surprised if we see more and more of these hybrid attacks where they use one vector to establish confidence on that victim employee and then use the traditional vector to make them click or install something on the end point. Look, I've been in security a long time, as have you.
Right. Do you ever get discouraged? You, you, you shouldn't.
Right? It's, it's, uh, like I said, there is always, uh, going to be cat and mouse game over here. There are certain things that you could do to be more proactive.
Um, when we talk about zero trust, it's also a journey. Every milestone you hit, your posture goes up. But then bad guys are also trying to evolve their tactics.
And you need to be aware, you need to have that situational awareness to make sure you're, you're getting in the right shape to defend against it. Agreed. Agreed.
Um, what's been your impressions of the show this year? Uh, uh, I I, I Feel like your vibe, Uh, definitely more crowd than last year. Uh, yeah.
How to say that? Um, uh, unfortunately I spent a lot of time outside the show floor, meaning, meaning all the large customers, uh, but a lot of ai, uh, agentic ai, um, solutions around securing AI or leveraging AI to be more productive. Um, look, we are in that stage where there's plethora of solutions in this space.
Probably our next one to two years, we're gonna see about 80% of these fizzle out. Yeah. And there will be 20% that will actually result in some good, you know, pragmatic.
But that's market at play. Exactly. Right.
That's the market at play. I, um, I don't know. I mean, you know, there was this whole rebranding, it's RSAC conference, the RSAC company, they're trying to build a community and a membership that'll go year round.
I think it's a good thing for the industry. Yeah. Right.
I think it's a good thing. I think, I don't know if you saw the CS a, well, not csa, the Department of Homeland Security mm-hmm. Talk yesterday.
You know, I think at a time when maybe government is pulling back from being the, the center of the Yeah, Yeah. Collaboration exchange. Yeah.
Yes. That we need an RSA Yeah. Yeah.
To, to provide that role. Yeah. No, and and, and it's one of the most attended conferences as well.
Well, it's the biggest security. Exactly. I mean, I mean, the fact of the matter is no knocking anything, but it's twice the size of Black hat.
Exactly. Yeah. Maybe more now.
'cause as you said, I think it is bigger this year than even last year, and I think last year was 40,000 people. Yeah. So leveraging this event as a form for collaboration, and even making it year, year long around, like you mentioned, I, I think it's a good step.
Absolutely. What can we expect to see from Zscaler soon? Well, uh, don't get, don't say anything you're not supposed to.
Yeah. You, you don't have to worry about that. Yeah.
But yes, no, um, look, there is lot of, uh, investments that we're doing on both a, the zero trust everywhere. P so zero trust for users workloads, IOTO, um, uh, even even the public cloud environment. And then because we see such high volume of data, so on any given day, we're securing half a trillion transactions globally, or 9 billion threats and policy violations that are being seen.
We're spending a lot of time leveraging that telemetry to build AI powered operations. So both from security perspective, this is a security operations, uh, applications. And then there is also IT operations applications that we're building.
Uh, there was a recent acquisition that we made last year, uh, in the data fabric space. Yes. So that is now fully integrated.
We're building apps on top of it. And the goal over there is the inline exchange is protecting our customers from threats inline, but then those learning also flow in over here. And we are able to do correlation, bring in additional context, including non Zscaler data set, and then influence policies controls back into that inline exchange.
So that's, that's something that we're pretty excited about. That is, and you know, it's interesting is that it's no longer just attack detection or response even. It's, it is the whole picture.
Zscaler, you know, I look back and I, as I said, I've seen Zscaler grow from its start the, the breadth of the platform Yeah. Speaks to the maturity Yeah. Of, of the technology.
Anyway, that's a wrap. Yep. Thank you.
Enjoy the rest of RSA Say hello to Jay for me. Thank you. Yep.
Zscaler here at RSA conference. We're gonna be back in a moment. Stay tuned.
You're watching Techstrong tv. Welcome back to Text on tv. Lisa Martin here coming to you live from Wacon West at RSAC 2025 in San Francisco.
This is Techstrong's, 10th year of covering RSAC. We've been having some amazing conversations today with cybersecurity experts, which, you know, 'cause you've been watching since we started. I've got two great guests here next here to talk about what they're doing in the federal space.
Bridget Gleason joins us, the CRO at Space Lift. And Irena Deko, the CEO at Knox Systems. Ladies, it's great to have you on the program.
Thank you for joining me. Great. Thank you.
To be here. Love talking partnership stories. So let's, let's do it about for each one.
Okay. Space lift. Give the audience an overview.
We're talking about infrastructure as code, but what's your secret sauce? Policy driven, governance, security. Enabling teams to go fast.
It's all about velocity, but you can't sacrifice on security and governance. So that's really, that's really the secret sauce. And you are enabling developers to go faster.
You're enabling platform teams to have more control. Right. The whole, the whole ecosystem to go faster because the name of the game is getting your software out there.
Yes. And you can't do that if you're not able to deliver it on reliable, secure infrastructure. Absolutely.
So, and that's all that we're talking about today. Yeah. Is, is around security and it's becoming more and more challenging and more and more important.
Absolutely. We're seeing It's kind of a double-edged sword because it's essential, yet there's so much more software being developed every day. Right.
And that threat landscape just gets more and more amorphous Right. And sticky and Right. It, there's no surprise that we've seen a huge uptick in demand.
Yeah. At Space Lift. I wanna give us a background on NOx Systems.
Where you, where you base, what do you do? How do you partner with Space Lift? Thank you.
Well, Knox, uh, is a very simple concept. We are FedRAMP as a service. Okay.
We host our customer applications in our federally compliant cloud. And we get them FedRAMPed in 90 days for 90% off of what it takes to do it alone. Oh my gosh.
That's huge. And so we are so excited to partner with Space Lift, uh, to be able to bring them into FedRAMP, but even more importantly, to be able to use them for us, we manage, uh, over 20 applications, including Adobe's Federal Cloud. Okay.
And we need tooling to do that in a compliant way. Yeah. And that's exactly why we're so excited to be using Space Lift to do so.
And how new, how long has the partnership been going on? It's being announced tomorrow. Oh, congratulations.
So you are like, This is hot. We're breaking news Here. You're breaking news.
Ladies news. Thank you. I'm Excited.
Hot off the press. And you know, when our, when our CEO came to me and was telling me about Knox, and like you said, 90% discount, 90 days, I thought, there's no way. Yeah.
And for us, we have this growing demand. Our growth is being fueled right now by large enterprise government organizations, lots of regulatory industries. And so having this FedRAMP piece is so significant for us.
And also being able to deliver that to Knox is really exciting. Is This opening the door for space lift in the federal space? Yes.
To some, some don't require FedRAMP. Okay. And we're able to satisfy that.
But many, many, many do require FedRAMP. The other that Irene and I were talking about as we were walking over here is large enterprise. Also, when you have that FedRAMP certification, they know that you've got a, a very strict security checklist that you've already complied with.
Yeah. And so I think that's gonna accelerate also time to market for some other companies that we're working with. Well, You're giving them the confidence Are thrilled.
Yeah. You, you're giving them the confidence, the customer base, A hundred percent of what You're able to deliver. Why would some federal agencies not be required to do be FedRAMP certified?
Is that, You probably know that is Yeah. So I assumed it was a blanket requirement across, so the, The, the situations are really, if you're delivering on-prem and space Lift is able to deliver both the SaaS and an on-prem. So if you do on-prem, that's fantastic.
And you're able to, to deliver to the government. Yep. Because effectively you're air gapped.
But for the many, many, many SaaS solutions out there. Uh, and to be able to, to operate at the speed of SaaS and at the scale of SaaS, uh, that is where FedRAMP comes in. And that's really where we're enabling space lift to, to really accelerate.
Okay. Got it. Talk a little bit about what federal agencies will be able to achieve with this partnership.
What's in it for them? Absolutely. So, uh, I'll, I'll start off right off the bat.
We have 15 federal agencies that serve as our authorization to operate providers. That means they are our sponsors. And they are thrilled about this because what it means to them is they know that the applications that sit in our boundary, the applications that they consume, are that much more secure, that much more, uh, observed and, uh, compliant with all of, not just the FedRAMP regulations, which are very important and really the name of the game.
But also there's many additional regulations around now AI coming out Right. Around cryptography coming out. Yeah.
Because of course, software is moving so quickly. Yeah. And so what, as we harden our stack with tools like Space Lift, um, it means to them that they feel a lot more confident.
Right. Consuming from our cloud. And, You know, I do a lot of marketing.
I I've been in marketing for a long time, and confidence is critical. It's not a marketing term that is to, to be able to give a developer a platform team a, an agency. The, the trust and the confidence that their applications are secure is not table stake.
It's table Stakes. No. It, it, it, it absolutely has to be.
And ire and I were talking earlier today about how this, this administration is looking to modernize a lot of the infrastructure. Yes. It's, that's gonna require for them to do it a lot more software companies that are certified to, to service the, the government.
And it's part of the reason I'm sure you're seeing a big demand. We're seeing a big demand because for us to fulfill that, we've gotta satisfy these requirements. So as you said, it's trust, But it's Also, there has to be the security.
Very real security. And it is frightening Yeah. To think about with AI and some other tools out there that the threats are getting bigger.
And so being able to have a platform like Space Lift that is very strong around security, compliance, governance, et cetera, is critical. One of the things we heard today, we were at the same, um, talk this morning, was companies that want to allow their security folks who are working on compliance issues, everything you do need to do to satisfy compliance, they would like them to actually be working on security issues. So a platform like Space Lift that can take away some of that, those compliance chores and busy work Okay.
Will enable some of the security people. What did they say today? How many?
500,000 open positions open positions in, in cybersecurity security. Yes. Right.
Yes. So we've gotta make sure that the people that need to be, that can be doing security are working on it. And space lift can help take away some of the other compliance and auditing and some of those other requirements that we can help fulfill through automation.
Right. And so you have the security folks focused on what they Need to focus and that's what they want to do. Developers wanna develop, security professionals, wanna secure by being able to offload and automate some of those, I don't wanna say menial tasks, but tasks that take time and resources is huge.
Well, we, I don't know if you know that we released an AI agent about two weeks ago, uh, Saturn head ai, and I mean, you're talking about the mundane, repetitive tasks for DevOps engineers. That's finding out what happened when a deployment fails. Yeah.
And it requires looking through very complex voluminous logs. It's mundane, it's repetitive, and it often requires a more senior engineer Okay. To be parsing through those logs.
So our agent can go analyze the logs in plain English, give you a description of what happened. Probably like that. Like that.
Yep. And then also these are the things required to remedy it. So again, making sure that we've got the more senior people deployed on the really the highest, A highest tasks.
Yes. Yes. So from a sales perspective, are you selling into developers?
Are you selling into security teams? Is It both? Yes.
Yes. All the above. Yes.
Okay. We get interest from the developers, we get interest from security, we get interest from CIOs, we get interest from platform teams. Okay.
It kind of comes a across the board, depending on what their lens is to look at It. Okay. What excites you?
I mean, there's so much you talked about ai and we can't go to a conference without talking about ai. Right? You can't even, A fashion conference is gonna be talking about AI and fashion, I'm sure, but it's been around for so long yet, the chat, GPT Catalyst a couple years ago just brought it front and center and everybody is diving in head first, but it also opens up vulnerabilities por and more opportunities for the bad actors.
What excites you about some of the positives that you are seeing in the security space where AI is concerned versus all the, the fear that's out there? Yeah. Well, I can tell you from just operating our federal boundary, um, it is a game changer to have AI reasoning agents that we can custom train on our data run with open source models, that we are able to fully understand and actually take those agents and scan our boundary for issues with the boundary not being compliant with FedRAMP.
So rather than having to do something manually only once a year or once a month, or as often as you can get to it, we're able to truly do continuous monitoring. And that is only enabled by AI reasoning agents. Um, which is why we're so excited because, uh, yes, the bad guys are gonna move fast.
Yeah. But we're able to move faster. That's so important because it's, it's like the AI arms race.
Yeah. We see it country to country, all the competition going on, and we see every organization, um, embracing, really embracing ai. It's rare if I talk to A CMO who's not embracing it, at least generative ai, and now it's a agentic AI as well and ephemeral ai.
Talk a little bit about the go-to market strategy sales, CEO. What is that gonna look like from both of your lenses With regards to the partnership? Yes.
Uh, again, we were talking about this on the way over. I asked Irena, so when will we be FedRAMP authorized? Exactly.
And she said, June one. June one. That's a round hit go.
So again, I've got, I've got a pipeline of opportunities right now of, again, large enterprise regulated industries, government organizations that have already reached out to us and are looking at space lift. So I think we'll continue business as usual. We just, now there's a gap that we, we hadn't filled and we thought it was gonna be, honestly, Lisa, more than a year, and very expensive for us to do it.
So this is like Christmas For me to Have this. I mean, it's so, it's so thrilling. And I think for our customers as well, because they're trying to do the same thing.
They're trying to create resilient Yes. Scalable, secure infrastructure for their environment. So to be able to satisfy that just feels really great.
I think it's, it's definitely a win-win. It sounds Like there's all already a lot of momentum from a demand perspective. Are you seeing the same thing on the NOx side?
Absolutely. So part of this partnership is actually, we at NOx are installing one space lift worker per application inside of our boundaries. So that's already, uh, almost 20, uh, uh, workers installed.
And as additional customers come onto NOx, they're using space lift. But the other thing I'll tell you is that even for example, one of our customers, as I mentioned, is Adobe, they're now starting to look at space lift as something they might wanna be using, even beyond just their federal application, but in their development team, uh, beyond. So it's a, it's a really, uh, because it's such a broadly applicable tool, not just for federal security, but much more beyond that.
It's a, it's a great place to, uh, to really, uh, spread the word. Sounds like you guys are gonna be awfully busy. Yes.
That's a good thing, right? Absolutely. I just wanna shout it from the mountaintops.
I'm so enthusi enthusiastic about. I love it. I'm so enthusiastic about the partnership.
Again, it fills a great gap. Yeah. I think we're gonna be great partners.
It's so mutually beneficial and, uh, reinforcing Yes. Of one another. So we're both, we're really excited about it.
And, and you're gonna be able, you know, we talk about cyber resilience all day long. It's a journey. It's not a destination, but it's also one, like I always wonder how can organizations truly become resilient?
How does this, a facilitator of that? Because resilience is the goal for so many organizations across industries. Well, this is one, this is one step towards that.
Absolutely. You know, one, one thing to, to really, um, I think the, the position we take at Knox is to be, uh, aggressively conservative, right? Okay.
And you can only be aggressively conservative in your security practices, in your, uh, resource configurations is if you're able to one, automate, but be, observe exactly what you're doing. That's why we use infrastructure as code, and we always have, that's why we wanted to use space lift right out of the gate. And, uh, and we, we said, please, would you get FedRAMP please so that we can, we can use you.
Um, but that is the only way to stay resilient if you're able to automate and be kind of everywhere, all at once, all the time. Yes. That's the only way.
Right. What do you hope for? Last question for both of you.
What do you hope here we are almost in May, June one hit the ground running. What is kind of your dream for the rest of 2025 as partners? Well, I can tell you, uh, we are gonna be bringing on a number of, uh, uh, applications into the NOx boundary.
Every single one of them is going to be running, uh, space lift workers, uh, to orchestrate their, their environment. Um, and what I'm so excited about is, uh, to really be able to, to see this, you know, mass machine humming. Yeah.
And, uh, and you know, there's, there's no doubt that there are going to be, you know, there, it wasn't that long ago that Log four J took our entire industry down for, you know, months. Yes. And, um, there will be more.
And what I'm very excited about is that we are, we are building, constructing this boundary, um, in a very hardened way, in a very, uh, uh, thoughtful way. And space lift is a key part of that. That's critical.
Ladies, thank you so much for joining me on Techstrong tv. It's been great to have you. Likewise.
Learning about the partnership. Congratulations. The news comes out tomorrow.
We got to break some news. I always love it when I get the chance to do that. But it sounds like you're creating that resilience, that organization, not just the federal agencies, but in every industry.
That's Right. Have to have, that's right. This definitely goes beyond just federal agencies, so it's really thrilling.
Well, congratulations again, and we'll be watching your trajectory. And we thank you for sharing your insights on text on tv. Thank you.
For my guests, I'm Lisa Martin. You are watching Text Strong TV Live from RSAC. This is day one of Wall to Wall coverage, four days here on Text Strong.
Stay tuned. My next guest joins me in just a minute. Hi everyone, welcome to the Platform Engineering Show.
I'm your co-host, Alan Shimel from techron. And let me introduce you to my co-host here on the show. org community.
Um, first of all, hey Luca, welcome. It looks like from the blurred background, you your home in Milan still? No, I'm back to the van.
I'm in Madrid now. Oh, back in Madrid. Okay.
Yeah. Yeah, man, you are the Globetrotter dude. Good for you.
Um, so what did happen last time we checked in on you, you were in Milan? Yes. Did you go right from Milan to Madrid or what, what's been going on in your world?
Yeah, London this morning. London This morning. Oh, you just got taking the van?
Yeah. Yeah. And I'm taking the van back to Milan, so that's why I'm here.
Mostly. I'm, I'm, I was gonna go to Barcelona. We have some workshops that we're doing.
So apart from engineering workshops that we're doing tomorrow, no, on Friday and in Barcelona. And I was gonna fly there and back to Milan. Um, but then I was like, well actually, you know, anyway, logistics, but we wanted to bring the, the van over to Italy.
So I was like, okay, let me just land a day earlier, drive to Barcelona, and then drive from Barcelona after a work trip to Milan, which is gonna be a long ride, but hey, it's friends in between, so it's gonna be nice places to stop by. Good for you, man. That sounds like a nice road trip.
Good stuff. Yeah, Luca, so for this episode of platform, the platform engineering show, we're talking about steps to platform engineering. org, right?
Correct. And the article is actually show notes. Yeah, yeah.
We'll, we'll put the notes in the article is actually nine steps. I don't know if we'll go through all nine steps, but we're, we're gonna have steps, steps to platform engineering. Hell.
But you know, it's kind of a funny premise, right? 'cause we're here trying to say platform engineering is a good thing. It's a way out, it's a way to, it's a to scale's a habit.
Yeah. Right? Where, where does it all go wrong here?
That it could, it could become a hell yeah. Oh, so yeah. This, this, exactly, this stems out of this like nine steps of, uh, platform engineering had article, which actually steps from another article, which was the, I don't know how many steps of DevOps have that I had written prior to that.
And then it was interesting just to see, because your point, right? Like everybody was like, oh, you know, great, I just moved to DA from that was platform engineering. All my problems are solved.
Um, and then, you know, obviously you start seeing this like anti-patterns emerge within the platform engineering practice too, where well actually, if you don't do it right, you end up, you know, potentially even in a worse place than, than where you started. And so I think like, if we start from the top, like the first thing that I see a lot of people, a lot of teams, um, making is a mistake is, okay, let me take, you know, the sort of like hodgepodge of DevOps, cloud ops, SE infrastructure teams and just rebrand them into the platform team. Um, and it's actually interesting, you know, we start, uh, hosting these trainings or, um, organizations to go through from a, you know, to, to kinda like upskill their team.
And one of the things that I see resonates the most with, um, with platform leaders is this, right? They say, you know, every, every time I say this, everybody knows. They're like, oh my God, yes.
So true. It's just like, I, I inherited this legacy of different teams. Now they're all sit under me, they're all part of the platform engineering org.
But actually nobody has a clue as to what platform engineering even is, right? And so I think like the, the first mistake down this like, you know, um, sort of like slippery slope of, of the down platform engineering, how is this idea of like, okay, well let me just like rebrand whatever I have inhouse right now with no upskilling, no retraining, and just hope for the best, right? And that just doesn't work, right?
Because you have people that fundamentally approach infrastructure the way the, the, the, the relationship between developers and infrastructure as well in a very different way than, um, technically what a platform engineer should do. And so without retraining, without shifting the mindset, it becomes very, very problematic. And that leads right into the, sorry, second step, which is this product mindset, right?
Um, that we've talked about before. We had a full episode on platform as a product, as one of kind of the core principles of platform engineering. And that's really, uh, you know, also what's, what's missing a lot of times because there's no retraining, building a platform just gets treated as this kind of like one and done, um, sort of infrastructure project that's like six months or whatever.
Um, you know, I'm gonna teach developers something new, I'm gonna implement something new, and then I'm gonna move on to the next thing. And of course, that's also recipe for disaster because like we said before, previous episodes, really the point of building a platform is that it's an internal product. Um, and it has internal customers, the application developers or other users as well, security teams, architects, even the, the, the infrastructure teams themselves can be used of the platform.
So the point is, you have to ship it as a, as a product, um, implement product best practices, and really think of it as a product, not just from a technical perspective, but also from a business and go to market perspective, where your internal market is your, you know, internal tam, the total adjustable market is essentially the size of your engineer organization. Um, and so that that mindset shift towards platform as a product is essential, is part of the retraining, of course, that, you know, it can also help obviously having, um, you know, a, a a broad product person or multiple product people within the platform engineer organization that lead this transformation. It helps if executives understand this and support this change.
Um, but at the end of the day, that is another thing where if it doesn't happen, you know, you're, you're, you're setting yourself up for, um, failure, right? Um, so maybe we can start from there, um, and then we can kinda like dive into, into, into other, uh, steps too. But I think that's really where we see in the community the first kind of roadblock and, and where, you know, the trainings and the courses that we've done resonates so much with the, with the market because, um, you know, everybody understands this idea of like, okay, you know, platform engineering can solve all these problems, let me go do it.
But then if you don't do it right, if you don't upskill your people, it's very easy to, you know, to get stuck very, very quickly. Yeah. You know, I, I think one of the things about that too, Luc, is something you said right, right off the bat, which is for a lot of organizations moving to a platform engineering model, we could call it that, right?
Yeah. Is almost like a lot of recycling instead of creating new, right? Mm-hmm.
Mm-hmm. And granted that there's nothing a matter with that per se, right? You, you, you do wanna Sure.
Reuse these assets, and you do wanna make it all work, you know, tightly, but you, you can't, you can't just put a fresh coat of paint and change the sign above the door and say, voila, you know, life of engineering. Yeah. You know?
Yeah. It, it, it takes more than, than just a fresh coat of paint and a new name on the door. Um, and I, I think, you know, I'm guessing, right?
You guys have the course. I don't, I haven't taken the course, but I would imagine it has to start off with, you know, preparation is, is the key to this, right? Having a plan of, of, of instituting this platform engineering model across the, the organization and working with DevOps and SRE and, and ops and, and security and all right, everybody's gotta get buy-in.
Everybody's gotta understand what it is. Everyone has to understand what they've do differently or what they've gotta upskill on, or, or how this all fits in, like anything else, right? Fools rush in where, where wise men dare to tread, right?
You, you've gotta, you've gotta, it's all in the prep, I would imagine. Yeah, absolutely. And, and, and I think like, um, few things that you said that I think are, are worth unpacking.
One is this like fresh thing of paint, right? Which is so true. Like this is one another huge, I think, um, you know, challenge that emerges when people are just like, okay, I have a platform engineering bandaid because you know, my execs write on Garner that is cool and they should invest in it.
Um, and so now I need to go do it and I need to show something for it, right? And so the first thing they do is they focus on, you know, the, you know, re re repainting the facade, really, right? So it's like, hey, let's, let's, let's put like some, some ui, some portal, something right on top of the entire setup and call it a day, right?
And it's like, we're down platform engineering. And of course, the problem with that is that actually, you know, I do think that that visualization is an essential component of platform engineering. Um, but it needs to come with a layer of automation and ization underneath it.
Otherwise, what you end up being is, um, you actually get the, the, the, the sort of like the second step of buy-in by executives because they're like, oh yeah, this, this looks great, right? Um, it, it's, it looks like we've, we've, you know, made a lot of progress and so on, but then actually there's no substance underneath. And, and then you end up quickly into place where you, um, you're sort of essentially misusing tooling that is meant to be frontend tooling, um, to build, you know, to build the entire platform.
And, you know, you can't, so you can like shoehorn your sort of like business logic into this, this front end module and so on. And, and, and, you know, you end up creating massive tech debt down the line. And that's one of the, uh, it's already one of the, I would say, another huge kinda like mistake and kind of like step to have is this idea of like, okay, start from the front and first, but also, you know, um, and so really not following, uh, architectural best practice, right?
Like, yeah, I think it's very important to understand that building a platform, it's just like building any application. Again, it's just an internal product. You need to start from the backend and then figure out, okay, what pretty facade?
What door do I add to my door, to my, to my house, right? Um, you don't wanna start, as you said before, from like the house and the wind, from the, from, so like the doors and the windows, and then kind of like add, you know, the walls and the foundation, uh, after, right? Um, so, um, so, so I think that's, um, that's like a very, very important thing, um, to avoid.
And then your point, right? It's about planning. So, um, this is where I think one of the, um, one of the most significant standards that, that have emerged in the commute in the last couple of years have been this reference architectures for enterprise grade platforms.
Why? I mean, I don't know if you're, you know, if you remember like two, three years ago when people started talking a lot about platform engineering, um, you know, like in places like CubeCon and saw, I remember, you know, three, four years ago, I had to explain to virtually everybody I met, okay, what is platform engineering? You know, what do we mean by this?
What do we mean by that? Um, and then, you know, a couple years ago there was this clear inflection point where you could, first of all, everybody was talking about it and everybody was interested, but then also you could finally have a real conversation about it because there was this visualization, which again, it's why I think it's so important to visualize thing. There was this visualization of what a platform, uh, target architecture can look like, right?
And all of a sudden people had a common ground to have that conversation and to think about, you know, backend front end, okay, what do we mean by this? You know, how do this security tools interact with our platform? How to observability tools interact with our platform and everything else, right?
However, I also think it's important to mention that, um, and, and so, you know, like the lack of a plan is certainly another step to how, right? But then I think there is a subtle step right after that, which is, okay, I have this beautiful target architecture that I want to build against. Great, let's go build it.
And then the mistake that people make is, okay, let me try and do everything all at once, right? Um, and, and build this like, amazing platform layer that is super secure that has all observability built in, that is making everyone happy, right? And that's, that's I think, a one of the, the, the big problems here is because platform engineering initiatives touch so many different stakeholders, it's very easy to fall into the trap of trying to please everybody.
Um, and that is a, a sure recipe for, uh, failure in my opinion, because I think the way we should approach it is, you know, we've talked before about this idea of minimum viable platforms really taking, again, this like product management best practices of starting small and itrate from there. Um, but what starting small means is it both from a technical estate perspective, right? So selecting one, maximum two representative applications and their respective dependencies, and start from there.
But then also start with like one team, and especially one set of stakeholders, right? If you're trying to, you know, make the application developers, the infrastructure people, the security people, the architects, the executives, try to make everyone happy at the same time, it's very, very, very hard to keep momentum and traction for your platform initiative. Whereas I think, I don't know if you spoke, if we've spoken about this before, I know you and I have offline, but you know, we've, we've, um, I think it was actually part of the, um, the predict 20 20 25, um, predictions, right?
This, this idea of, um, the, um, the Pareto Pareto, um, Pato efficiency, right? Um, which is similar to the 80 20, the Pareto principle. Um, but there is a subtle difference, which is interesting, I think, which is essentially is, you know, in, in, in layman's terms, like, don't p**s anyone off, right?
So, um, um, which, which is like, okay, you need to make life better for some people, right? And, you know, in the case of developers, that's, that's restart the conversation. The DevOps cell is easy, right?
Like right now they're waiting for like two weeks to get an a database provision by their ops colleagues. Like to make that 10 x better, it's easy. You just cut it into minutes.
It's like self-service. Um, uh, so, so that is a 10 x, but then it's important that that doesn't come at the expense of, you know, getting your security folks mad because now you're making things less secure or, you know, um, whoever else, right? Like infrastructure people now, um, are mad because, you know, you built, you didn't build your platform, right?
So it actually, now self service means developers can just like click a button a hundred times and create a hundred different resources that then the, you know, infrastructure people need to deal with. So like, those are the type of of things where it's like, make sure that your platform really makes life easy for somebody, but doesn't, you know, is at, at worst a net neutral for everyone else at best in net positive. But it's never a net negative because the moment, even if it's like a 10 x better for some, for, for for few people, for few stakeholder groups, but even just like a minus 10% for somebody else, you can bat that somebody else is gonna, you know, like, uh, uh, like put up a crazy fight to stop this thing.
Um, and, and it's a strategy of the commons, right? That this like large enterprise or transformation run into because, you know, it is better for the organization anyway, but that person doesn't care because that person is now 10%, uh, worse off. And you bet they're gonna fight, you know, you know, they're gonna give up their life, uh, to block this, this platform initiative.
And that's kind of just the reality that we live in, right? You're dealing with humans and, and, and so just to kind of like put a ball on that, I think that's the, that's the last thing I would say is, you know, another huge mistake is just like looking at this as a technical problem to solve, which is very natural for engineers as opposed to this like multi-stakeholder complex cultural problem, which is really a human problem that we've talked about many, many times. And, um, and, you know, and that's the sure way to, to sail it, in my opinion.
That was a lot. I'm sitting here laughing. No, no, but I'm sitting here laughing.
'cause I, you know, we were talking before the show today about the Google migration going on here, uh, with tax strong f your chairman. And, and that's kinda where I'm at, right? It's just, it's more than a minus 10% for me.
It really kind of Yeah. Sounded like it rip at me. Yeah.
But, um, I don't care how good it is. It's not, it's just not, you know, I'm going to not accept it so quickly and it's gonna, they gonna kind of make a Right. I, and I, I, but I think that that's a good lesson.
And, and this, and, and quite frankly, there's a DevOps lesson too, is it's not just about the technology. It's not just about the technology. It never is, first and foremost is people culture, right?
Because you can, it, it's a lot. It's pushing rope uphill to get people to accept technology or process that they don't buy into if they don't buy into it. I, and look, I this 30 plus years in business, right?
35 years in business. Yeah. I, I've run into this, not just in it, but in general, if, if your team doesn't buy into what you're selling, right, what you want them to do, it is, it's pushing rope uphill.
You don't want, it's shoveling sand against the tide. You're just not gonna win. Yes.
Right? You gotta win 'em over. Yes.
Now, who is, who is pushing back, um, on, on DevOps, right? Because to your point, it's a similar, like, it was like a cultural change, right? And, you know, I feel like looking back, it feels like everybody was agreeing, but I'm sure like not everybody was agreeing, right?
So up here, everyone was agreeing, sitting around the campfire singing kumbaya, right? Right. But the fact of the matter is, it's the same people, you know, and I'm not this and anyone, but a lot of engineers and, and folks say, yeah, that that culture stuff is all fine and dandy.
What's the ICD tool am I using here are get from Jenkins. Jenkins, you know, Jenkins, Jenkins Jenkins, and what's my plugin and what's that? And, and that's what it's about.
It's about moving, you know, shifting security left. I don't care. But you know, we pastor, we don't need no testers.
I'm using this new testing product, right? Yeah. That's automated.
And, and so like, they give their mouth moves when they talk about people and culture, but at the end of the day, they don't mean it. Yeah. It was about the tools, all about the tools and Yeah.
And it can't just be all about the tools. I mean, I, you know, I'm sorry, but tools are important, don't get me wrong, but I don't even know if they're the most important. Right?
Right. I still think people is where it's at. But let's, so, so look, let's assume we, we get off to a good start.
We do the right things from the start and, and we're up and moving, right? We're, we're progressing mm-hmm. Down this platform, engineering on the road to heaven, stairway to heaven.
What could go wrong that makes the U-turn, you know, after we, like, after the train left the station, right? What else? Where else could we go wrong here?
Yeah. Well, I think it's the same things, you know, um, it's just like a later stage, right? So the, uh, I do think that that getting off the ground is the hardest thing.
And what's also interesting is, you know, I think it's important to understand like platform engineering is mostly a enterprise thing, right? Uh, or at least like mid-size sort of like engineer organization and up, right? Because that's where the problems that platform engineering solves are most badly felt.
Um, and so, you know, um, and so it's important to, I think mention like you basically in these situations, in this companies, you never start greenfield. Like there's always an existing legacy brownfield complex enterprise thing that you need to deal with. Um, and so it's not like you're kind of starting this platform engineering initiative in a vacuum anyway, right?
So even if you're starting new, you need to start wherever you are. And, and, and then if you already are on track, it's actually, you know, because I'm seeing it where I go in and I do these trainings with like large enterprise, and some of them are really at the early stages of their platform journey. Some already have like a platform team of like two, 300 people.
And granted, some of them are just rebranded, right? And they need training. But some of these people are proper platform engineers that have been building platforms for years.
Like they know what they're doing. Um, but they're, the challenges are very similar, which is like, how do I get adoption? How do I get buy in from different, uh, you know, uh, stakeholders, whether it's executives or others.
And so you're just at different stages of it, right? Which is why, like, the way I think of platform engineer initiatives is, you know, you have this like MVP phase. If you're at the very beginning, um, then you have this kinda like production readiness, right?
When you want to go from like, okay, you've proven the, the proof concept all the way to, okay, let's go to production with the first set of applications in the first one or two teams. And then once you're there, you go from production readiness to all, you know, all the way to full scale adoption, right? Just like, okay, we're gonna go to the entire organization.
And every step of the way across that journey, you have, you know, basically just like a permutation of the same set of challenges, right? Which is like, how do I convince people? Um, right?
And, and maybe like the first time is like, well, how do I convince the first team? And the first team is like, you know, you probably wanna start with like a, you know, pioneering team. I, we call it in the community that is like, um, you know, the team that is, that are like more comfortable with like, new technologies, new setups, you know, maybe the first one that implemented Kubernetes and containers back in the days, or infrastructures code and terraform and stuff like that, right?
The one that you use to, you know, effectively like stress test new paradigms, um, and, you know, but so the set of challenges that you need to solve for them is radically different than the set of challenges that you need to solve for the nth team, which is, you know, the laggards effectively within your market, within your organization. And they, you know, they're just, they're not so with the firm, or maybe you need to figure out, okay, what is the right way of, you know, obstructing this underlying complexity while still giving them control? Because obviously they're the people that like control.
They are the people that like, you know, their infrastructure, uh, you know, to like being able to get their hands dirty, they like their arm charts, whatever. And then the, the, the latter, the, the last group that can just be like, well, we don't care. You know, we're very happy to click around, but it's like, it needs to meet us exactly where we're at because we're super lazy and I, I don't wanna, you know, you know, jump into another interface or anything else, right?
Which anyway, is best practice. Like you should always meet developers where they're at and the users in general. But, you know, so, um, and, and, and it is the same thing for executives.
It's a very different thing that, you know, at the beginning you're asking for, you know, like half a million, 2 million or whatever, depending on the size of your org, when then you're asking for like, you know, 30 million because you're, you're scaling this up, you're, you know, now you're like, you're no longer 10 platform, 10 people platform team. You're like a hundred people platform team, right? So, and so it's like, how do I, how do I keep realigning my platform engineering initiative to their priorities as their priorities change as well, right?
Because it might be that last year their priority was employee retention this year is, you know, my, you know, I need to cut my bottom line or increase my bottom line, right? Like, whatever, right? So, so it's like it's, and again, and, and it's always just like constant culture play of like, you know, as the organization evolves as this like complex organism, how, you know, does the platform evolve with it as it grows within it?
Luca, let's step back for a second though, right? I, I was reading an article the other day and it was like a crazy number. Like 70% of it initiatives are not successful.
They don't necessarily fail and maybe end up in hell, right? But they're not, you know, if this is the bar for success, they don't make the bar, right? Right.
Hell maybe is down here. Is this, is there a similar thing in platform engineering adoption curves where maybe we don't quite get to hell, but maybe we're a purgatory, right? For, for a time where, you know, we didn't get to heaven per se, and we're not in hell, but we're somewhere in between.
Yeah. Yeah. A hundred percent.
I think it, I think that's the na you know, I think that's the na the natural state of, of most, um, of most things in the enterprises, this kind of like stuck in the middle, right? Of like, you know, because it's just so hard. It's, it's, you know, you have, you have, you know, at the beginning it's easy because maybe it's easy, right?
Because you have this like, set of pioneers that are like driving change. They're really passionate about it, right? And then it's like, okay, you know, and you see that's, that's why I think it's very, very important to think about it through the lens of a product.
'cause you see the same thing with any product that goes into any market, right? Where it's like, okay, you know, it, it requires, it's a different thing to get your first million revenue than, you know, the, your first a hundred million of revenue and then you're billion of revenue after that. And it's like, how do you evolve across all those things?
And so, and, and it's so easy for, you know, and, and, and, and so how many unicorns do you get? Very few, right? Um, and, and the reality is that most people, you know, end up on some, like tens of millions of revenue.
And that's, that's kind of like where everybody's happy, right? And, and so I think that's also the thing is, is like, you know, do you, you also need to keep dr like have an intrinsic and extrinsic motivation to keep driving this forward where, you know, maybe the had of platform who's so passionate about your platform engineer initiative is content now with having onboarded like your first like 10, 20% of estate, 20% of teams, um, you know, out of like 10,000 developers, that's already like a huge success, you know, and, and, um, and kind of like happy days and they moved on to the new better paid role or the next company. And, and, and so like, and then there's no driving force.
So I think this stuff is normal, happens all the time. Um, and this is also why I think, um, at the end of the day, the, the more successful platform engineer initiatives that I see are, you know, our, our prioritized across the, you know, throughout the, the, the sur chain of command all the way, especially to the, to the executives. Um, because you know, when it is, like, it's something that really, yes, you need to consider developer adoption, yes, you need to consider like all the different user preferences.
But at the end of the day, I can tell you there are, and this is where I think it also becomes a, not just like a cultural, interesting cultural conversation within the organization, but, but especially like also across like actual culture cultures, like we traditionally define them, right? So like across different countries and different regions in the world and so on, where, you know, I think we said this before, but there are clearly like platforms, initiatives, and, you know, more top-down cultures are more successful, um, because they're just top-down imposed. And, and that's it.
You know, that's what we do, period. Like, there's no conversation. It's not a discussion, it's just what we do because we're a regulated bank and, um, and the developer doesn't have much of a say, right?
Um, now I'm not saying that that's, that's the ideal state, you know, because every organization is sort of different, although not as different as they think they are. You know, everybody thinks they're like a special snowflake. Um, but, um, but at the end of the day, um, you know, having that, uh, if, if you can have that top down thing, that's where I think you can really drive and sort of like, you know, hit escape velocity and, and, and, and kind of like get to the entire company.
Otherwise, it's just, you're gonna be relying on how good that particular leader is within the organization, um, and how motivated they stay throughout the, the hassle of it, right? And then it's just like a founder, like, is the founder happy with like a 10 million valuation or a hundred million valuation, or are they one that kinda like shoots for the stars, right? So, um, it's, it's a little bit of that.
And I think even more complex because, you know, you just add an entire politics layer within these organizations than I, I think you don't have, actually, if you think about like, you know, I mean, you've done a lot of startups. I'm doing my, my first one, but, but it's like the, the, um, the, you know, you, you actually have a cleaner discovery mechanism with the market, um, because I'm selling something. If they like it, great.
If they don't like it, I need to change, right? Like, um, whereas in, within an organization, it, you know, when you're building an internal product, the, the, the feedback is not that direct is not that instant. And you have all this sort of like derailing, CIO says like, actually, we need to do AI now, right?
So like, that's actually what happens. And so like, I think it's, it's even easier to, to, to get lost in all of this and, and just go like, look, we're, we're 30, 40% of the way there. Well, you don't get clear, you don't get clear signal, right?
It yeah. When, when you're selling to consumer or even a B2B, you as a start of your small organization, customers tell you, yes, no, maybe I don't like this. I like that when you are going internally, there's the politics and the, there's just no clear signal.
I'll, I'll leave it at that. Yeah. You know, but it's an important thing that you mention here.
And, and I've seen this over and over in enterprises through my career, call it the orphaned project or the orphaned, you know, movement where, right. You know, charismatic guy, high guy or gal high up the food chain, this is their baby, they're gonna push it through, and then either they lose their mojo, right? They don't have that kinda juice to put it through, or they leave the company, or, you know, something else happens.
And now all of a sudden without that top down push, all the naysayers come out. You know, all the people who said, I always, I never liked that. I never wanted to do it.
They made me do it. I'm not on it. I'm not on board.
You know, you, you get that a lot. And you know, this was an interesting thing. Oh, you know, you got paralleling the DevOps journey.
This was a huge discussion in dev in DevOps, is can you do bottom up DevOps? Can the developers and ops people say, Hey, this is, this works for us, right? Yeah.
And, and you know, the long and short of it was, yeah, you can get some bottom up, but you always need air cover, right? If you're just gonna do one little team over here, you know, off on the side, yeah. You don't need necessarily a, an exec buy-in.
But if you are going to do it at an enterprise scale, try to do it organization wide without air cover. You know, I have a good friend Gary Groover, he, he, uh mm-hmm. He used to do, he used to run software for HP printer division, and then for Macy's, the retail company.
Yeah. And he's written a few books on this, right? On why you need top down air cover.
Yes. You need, you need executive sponsorship for anything like this. I mean, it's just, yeah.
And all and all the way through, right? It, it's like, um, you know, it's like a lot of people, like when they talk about, you know, if you zoom out politics to the macro, to the macro level, right? Where it's like, oh, you know, China has this like multi five year plans, right?
And like, we're stuck, you know? And, and, and it's a little bit like that where it's like, yes. You know, like I, you know, capitalism is a great discovery mechanism, right?
But, um, but then it, it, you know, then you have this like, mutations of it where it's like chronic capitalism and all these things, right? Where it's like politics, it gets me with politics, and then it actually becomes a, a less good discovery mechanism or, you know, aggression engine actually than if somebody just says what, what we do. Right?
Um, uh, you know, so it's, uh, yeah, I, I, I, I think about this, um, a lot 'cause it's, it's, it's very interesting. And at the end of the day, you know, organizations are not democracies either. Like, they're not, they're not meant to be, right?
There's like somebody that just decides and then they just like, and, and, and, and, and that's how it works. This is why, you know, when you have like, nimble teams, it works. It's somebody that just, it takes a call.
It's what it is, period. You know? And they might be right, they might be wrong, but at least you're moving, right?
And then, you know, as you grow, you lose all of that, right? Yeah. You know what they say, democracy is the most in the best of the worst form of government because it's so inefficient like that.
And yeah. And there is times when, you know, a more structured, kinda, this is what we're going to do. Path does work.
The Navy, the is in the Navy. Yeah. There is none.
Anyway. Hey, Luca, we're about outta time, man. I wanna thank you for joining us today.
Thank you. We, we, we have the, uh, the URL for this article. You can go check it out.
Uh, we'll be back on with some more people. We're working here on the platform. We're very excited.
And, uh, you are, you are headed in the van on the way. Well, you're going to Barcelona, then Milan, with a lot of stops in the way. Yes.
W we'll catch you on the road for the next episode. Will do. Thanks Alan.
Thanks everybody. Hey, Yvette, thank you. Thank you all for watching.
I hope you've enjoyed this, this the Platform Engineering show. Do check it out, uh, on your favorite platform, uh, platform, not Plat platform platform, your favorite podcast platform, apple, Spotify, whatever. You can get it on Text junk tv or any number of places online.
Until next time, though, is Alan Shimel and Luca Galante for Platform Engineering Show. We're out. Hi everybody.
Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jodi Ashley, executive producer here at Techstrong, here with my co-host Tracy Ragan, creator and CEO of Deploy Hub. And in her spare time, she does a lot of work with the Linux Foundation.
Before I introduce today's guest, I'm gonna give you a quick update about what's happening here at Techstrong. com. Be sure to go check it out.
I'm launching a series to go along with it on texturing TV with webinars and, um, biweekly episodes. So you definitely wanna tune into that. We're gonna, we're getting that rolling in the next, uh, two or three weeks, so it should be ready for you when, after you see this episode.
Uh, we have virtual events coming up. We're gonna be at CubeCon and London, come, uh, April. So if you're around, be sure and check in and say hi.
And if you're interested in doing an interview, reach out to Text Strong and, and we can hook you up with that. com, and be sure to tune in every day to Text Strong Do TV for all of our great shows and interviews. All right, Tracy, what's on your mind today?
Well, I think I would be mistaken not to say that, uh, deep Seek is on my mind. Uh, and in particular, you know, if it's true, what they're saying about Deep Seek, and they have a, they, you know, they have a different way of building these models, and a couple of university students with $6 million was able to do it. Um, we won't talk about, you know, the, the, um, the, the, the, the funding that went behind them, and if they shorted, um, Nvidia, that's a, you know, an interesting topic.
But the, the, the really, I think the lesson learned here is we're always disrupted, right? We're constantly being disrupted. And in this case, if what they're saying is true, um, it proves that our current VC model and our funding model for companies is not working in the us.
Uh, SoftBank just announced there and talked with OpenAI to do a $40 billion round for OpenAI, which means that there's a lot of money not going to other smaller companies that might be able to disrupt OpenAI. Now, I understand that they're in there to make money and they're trying to build up the biggest company that they possibly can. But funding is a, a limited resource.
It, it's not infinite, right? It's not, there's not just as infinite amount of money, um, that's coming through the channels that people can get. When 40 billion goes into one company, it's at the risk of maybe losing out on a company that's small, that may have a great idea and that may be able to build something better.
Uh, and not always, you know, spend a whole lot of money doing it. I mean, $40 billion is a huge chunk of cash. So I, I have to use the term, the democratization of VCs, right?
If we're not looking and we're not, if we're not really doing the research that we need to do, and we're just saying we wanna put as much money behind the guy that we think is gonna make it work, I think we're missing out. So that's my thought today, and it makes me sad. Yeah, it's been a big topic, I think, and I think it's brought, been brought up on every episode of Text Strong Gang this week.
So it's, uh, it's definitely a big deal. Sorry. Um, well, I am excited to introduce our guest today, um, Carolyn Nash.
Carolyn, tell us a little bit about yourself. Hey Ladies, thank you so much for having me today. Um, so my name is Carolyn Nash.
I am the Chief Operating Officer at Red Hat, and I know you two are big fans of the open source world. And so, um, you know, excited to be here. Um, and, and part of Red Hat, you know, which is, which is really founded on open source principles.
We, we develop and we, and we, uh, support open source software that fuels, I think it is 90% of Fortune 500 companies. So, um, at any rate, it's a pleasure. Just a little bit of it out there, right?
So, Carolyn, I really wanna first start this question off, you know, what are your thoughts about the, the potential of deep seek and is it really going to disrupt what we thought we had a future in building these massive AI data centers, you know, where, you know, from a, you know, from a personal point of view, not from a Red Hat point of view, where do you think this thing's going? You know, is this just really gonna disrupt how we see AI and demystify it? Yeah, it's, it's a great question and I, I mean, I gotta be honest, I feel like every couple of weeks or something that, that is like, we didn't see that coming.
I mean, right? Like, AI is changing at the speed of light, and what we knew a month ago is different from what we knew six months ago is different from what we knew a year ago. So Lord knows where this is gonna take us.
Um, but it is disruptive. Um, I think there's no question about it, but I think it's more of a question of what do we, um, you know, companies in the United States, other companies do about it? And does that fuel a new, I mean, I loved your point about VCs, right?
Like, does that fuel a new app? Like, don't rest on our laurels with ai. We have to continue to innovate and continue to think about how we can do this, and we can do this energy efficient, we can do this cheaper, we can do this faster.
And, uh, but it, it, it will disrupt. But I, uh, belief, and I'm gonna take the optimistic, uh, stance on this that, that, uh, that our companies are going to react and, uh, and come out even stronger in the end. Well, let's hope that is the case, is, you know, and now let's talk about it from a OpenShift perspective.
Mm-hmm. How is OpenShift adapting to these AI models, and how are, what are, what are you seeing from your customers in terms of what they're asking for? Yeah.
Well, I'll tell you, I'm gonna speak in terms of, uh, uh, OpenShift number one customer, and that's me. Um, so, you know, it's, I think about Red Hat technology. I mean, I run operations, so that's including, you know, including it.
And, and we run with every single, every single Red Hat product and, and many of the IBM products, uh, for reference point. But, um, as I look at it and I look at OpenShift ai, um, we're in a position, where're u we're using it. We're, we're no different than any other company as we're looking to do things faster, cheaper, um, safe safely.
And so with OpenShift and OpenShift ai, we're building, um, models and we're using them to change the way we run our business internally and how we support our customers as well. And we're not only, you know, using LLMs of course, but we're taking on something that's looking at smaller LLMs. And so basically we're taking them and creating a number of smaller LLMs that are really fit for purpose for what we're trying to use internally.
And that is all powered on OpenShift. And, uh, and the benefit of that is it really does address things in a faster, cheaper way. You're, you have to use less energy, you have to use less power, less GPUs in order to tap into these, these smaller models.
And that's exactly what we're talking about with our customers. 'cause again, we're, we're sort of our, our, our customer number zero, we call it our Red Hat on Red Hat. And, you know, from a, uh, from a security perspective on LLMs, I always felt that having those smaller models and having do models that have domain expertise, and if you could build a multi, uh, um, what do they call a multimodal LLM system where those are passing information to them, there's, it's almost a way to encapsulate it and, and protect it better, right?
There's a better, it is easier to do security around a small LLM than a, you know, I don't know, a 40 billion parameter LLMI don't know what they're up to, but Yeah, exactly. Huge. You know, That's exactly it.
And you think about like, so say like, let's talk about like internal support for any given company. You know, if you have something that's going in and, and you need whatever, I'm an employee and I'm trying to get some HR information on myself, right? If you think about safety and security and personal information, um, you wanna make sure you have a small, large language model that's really focused more on those, you know, HR type of topics as opposed to, and gets routed to the, they ask ar you know, ask hr, um, uh, support desk rather than being routed over to help me understand this customer contract and the terms and conditions on this one.
And so it, it, it not only makes it work more efficiently, but it protects our data better. And, and with the regulations and, and so much that we have to protect, it absolutely is a safety mechanism for us. Kind of interesting that we, and at the same time that we're talking about building Kubernetes decoupled architectures and getting away from the monolith, we, in ai, it's all model think, oops, are we, you know, sometimes I think that we don't listen to ourselves with what we're saying.
So I think it's, I think that model will be more interesting for enterprises to have small LLMs. Yeah. Yeah.
But then we have a lot of agents, aren't we? Like, you know, I'm, I do not like the ideal of agents because I think it complicates the stack quite a bit. And I understand that maybe we can't do it any other way, but there are other agents in the stack that we may not need.
And I feel like there's quite a few, there's quite a bit being thrown into production, even to do security scanning, opening up a container in production to see what open source packages were used, maybe some of that we can start scaling back on and pulling from the, you know, from where it was created at the DevOps pipeline and start building more intelligence into that and have a DevOps LLM. Why not? Right?
I love it. I love that concept. Yeah.
We do have to scale back too, because you mean, you think of it, it's, um, you know, you can build and build and build and build, um, but if we're not using everything we're building as well, I mean, we gotta do a little bit of cleaning, like cleaning out your garage, right? Like every now and then, you gotta go in and you gotta pull everything out, figure out what you're not using, what you don't need anymore, and then put it back into the garage, all organized and, uh, available for greater use. And you know what, it takes companies so long to do that, and they fight it and they struggle with doing it.
It's like, talk about hoarding mentality. Yeah. And, and it throws, you know, it creates just this great discussion around governance as well.
And, uh, yeah, because everybody is excited. Everybody wants to try these things. Everybody wants to do these things, but the more you create, the more, uh, how do, how are we making sure that as we're building and creating, that the experiments that don't work and that we don't want to continue with are actually getting edited back and removed.
Um, and it's just, you know, it's almost like, in a way it's governance, portfolio management, whatever you wanna call it, but making sure that, um, we're doing that in the right way. Yeah. I don't think we figured that out yet, especially around security and at all.
You know, we have SaaS, we have das, but we still have vulnerabilities that make it to production, and we're not remediating them very fast. The whole idea of chaos engineering and being able to respond to this, uh, to, to respond to a problem or vulnerabilities. I think it has been underserved and needs to get more attention because it's not really about, you know, root cause analysis all the time.
And especially as we start doing more AI work and we haven't figured out how to secure that. We just gotta get really fast at fixing things. Yep.
You can't prevent vulnerabilities, but you sure can react to them very quickly and, uh, and respond to them, uh, quickly and, and, and, and safely before, um, you know, damage is done. Yeah. I don't think we can, I talk to our customers.
I'm, I'm in the Boston office where our executive briefing center is, and, and I'm talking to various customers. Security is one of those top things. I mean, cost and efficiency and all of that has always been a topic, but security is, is more often than not something that really has to, you know, they wanna, they wanna discuss and they wanna find out what options they have.
Well, and what I think is interesting is just in the last few years, there was, there was a lot of push and pull. Um, we do a lot of security stuff here, and I would hear these conversations that people would literally argue about, but we should be able to prevent everything. And then everyone else was like, no, we can't prevent everything we've got.
We've gotta be prepared and we've gotta be agile and be able to work through it quickly. And I've seen that we can prepare for everything, just kind of disappear pretty quickly, especially as the AI has kicked in. Um, 'cause that's a tool that helps you respond really quickly, right.
Faster than ever before. But that argument is definitely move away. We, yeah, No, it's, it's Just not possible.
It's not Possible. It's not, it's not possible. It's not you, you can't, you just have to be prepared to react.
Is is what it is. And, you know, And I feel like there's a culture of complacency. Um, so for example, uh, deep seek gets released and then Wizz goes and says, Hey, we can see that, you know, a ton of data has been exposed.
Um, but does anybody care anymore? Does do they, do people really care? There was even an article I read, um, I think it was, maybe it had been the Navy or the Army that basically said, yeah, we know we should be watching for vulnerabilities, but if we need to get something out, we need to get it out.
And I'll take the risk even if I don't understand what that risk is. But it's a, it's a statement to say we're not do, we're not serving the community in, in terms of security. We haven't figured it out yet.
And the worst part, the worst part of all this is my opinion is we need investment to get it done. But when you have $40 billion going to OpenAI, there's not gonna be a lot of investment in security or cybersecurity in any way because we've become complacent. Yeah.
It's so true. And I, and I really appreciate your point about taking risks, because I think this is the, the, the balancing, you know, that we everybody's trying to do is how do you innovate at a crazy fast pace, but do it safely and take some risks, but take the right amount of risks in an area that is completely, you know, new to, to so many. And, uh, and, and you know, I think, again, in internally even things we'd, we've created a policy like every company has, right?
Everybody has their AI policy, but it's like version, I don't know what five or six now, because we have to keep changing it. Like, oh no, we, we over rotated and now we're saying no to everybody. Well, no, that's not the right approach, right?
And so then you're trying to tweak it, but, um, you really, you, you really don't know, but you also have to take risks. And, um, but just knowing, knowing where to, to place that risk pendulum is, is really the important point there. I think it's interesting though, how quickly companies, nations have responded to deep seek.
Like, we've let all this AI come and everyone's like, should we be worried? Should we not? Months and months go by.
I mean, this week, Italy, bandit, Ireland, bandit, Congress, bandit, everybody from the government, from downloading it. Um, you know, I think I'm, I'm just interested, and you wonder now if we're just, we flew to the other end of the extreme, but I'd rather see the other end of the extreme. Like Tracy was talking about all this vulnerabilities that people immediately noticed.
Um, I thought, I just thought it was interesting. Every, every couple hours I'm hearing another company or another Com country that says, we're banning it for now. We'll see how long that lasts.
But I just think we're, the response has been, I know, but I think the response has been really quick. Really quick. Yeah.
Yeah. Well, it's culture right now, and, uh, not following rules, not following policy. Oh yeah.
Taking big risk is where we are in our culture. So that's where we find ourselves. However, talking about taking big risk, you know, I was looking through your resume and you've made some big jumps in your career.
Ha ha. I sure have. How did you do that?
Talk to us a little bit about, you know, your background, how you, you know, climb the ladder to become the COO of Red Hat. That's an impressive job. And it's great to see a woman in that role, right?
Because it's taken a long time for us to get women in C-level positions. Yeah. Well, thank you.
Thank you for that. Sure. So, you know, it's, um, I mean, I started my career quite a while ago, but, um, I, I actually started out in public accounting.
So I was, I was an accounting major in college. Scratch that, I was an engineering major for a bar chapter and this, No, I can't know. Accounting is way more up my alley.
But at any rate, I, I spent, um, a good bit of time in public accounting, which I absolutely loved. And I think it became a, a great foundation for my career. Um, because I mean, I love public accounting.
It sounds really boring, but the reality is, like what you do when you're in audit is you have to understand how data flows through processes for flows through systems to ultimately end up as a financial statement. So it, it actually is an incredible foundation for how you learn about how companies make money and build assets. Um, but at any rate, I went into, um, into finance and, um, after I left public accounting, and I was living in Silicon Valley at the time, and so thought tech has got to be the place I go.
I wouldn't go anywhere else if I'm living in Silicon Valley. And so, um, got into finance there and how I actually pivoted out of, of finance was when I was starting a family. And I have, um, I have twins, uh, they're now adult.
But, uh, at, at the time I really wanted to continue working, but I needed some more flexibility. So I went part-time and I talked to my boss about it, and he agreed that like, you know, the, the finance and accounting doesn't really offer you that much flexibility. At least it didn't at the time in the role I was in.
So he flipped me into more of an operational role, more projects, things like that. Um, that gave me a ton of flexibility, allowed me to raise my children, and, uh, but also gave me this great experience and exposure to the intersection between finance, between it, between the business. And I really just loved playing in that space, kind of building on all that old public accounting days.
But, um, building in that space. And really from there, it just opened up my eyes to so many more possibilities beyond the track I was originally on. Um, I got into data and analytics, I got into sales operations, um, and played it.
That's Where I saw the risk. I mean, you went from hp, I think you went from, wait, you went from Hp? Yeah.
It's KPMG to hp to Cisco, to Cisco in sales operations. Yeah. I started, it's very different than public accounting.
Okay. Very different. See, maybe I'm wrong.
Absolutely. Absolutely. Still got the dollar signs though.
Yeah, yeah. No, it would, my time at Cisco was a wild ride. I mean, uh, Cisco is a great environment to really, they, they allow you, they encourage you to bounce around and try new things and continue to push yourself outta your comfort zone.
I actually had a fantastic boss at Cisco, and his point was always Carolyn, when you start to get comfortable in a role, like if you start to come into that little circle of comfort, it's time for you to go look for something new, go take on a new project, just ask for more scope, get something, never get in your comfort zone and never be complacent about your, your, your growth journey. Um, always be learning and growing and being just at a minimum, minimum mildly uncomfortable. And so it was really at Cisco where I took a, a tremendous amount of risk in, in leaving finance, yeah.
Sales, operations, data and analytics, business services. And, uh, and that I think, gave me the confidence when I came, you know, I took a, um, I that gave me the confidence to leave Cisco after 16 years and go to Red Hat. And I thought, this isn't gonna be a new type of company.
Something that I was really passionate about. I mean, because Red Hat's such a cool company, you know, built upon the whole open source communities and development model. It's also an open source culture for me is just been a blast.
And, and it's also a company that really encourages you, just helps you open up those opportunities. And that's where I actually bounce back into finance, believe it or not. And, um, and, and grew my career in finance back up and to become CCFO.
And then at that point there was some leadership turnover. And my, my boss at the time had asked me to take on it and security and a whole other things. I'm like, sure.
Right. Again, you don't wanna get comfortable. And I can't say, since I've been at Red Hat I've ever been in my comfort zone, it's been always right on that outside of comfort, which is how I know I'm at a, a great place.
So, um, so I, my, you know, my role as COO, you know, I paused it first, right? It as many of these things, like you got the little, I mean, who doesn't have the imposter syndrome? The little person sitting on your shoulder, talking in your ear like, no, Carolyn, you're not technical enough for it.
Mm-hmm. Well, you know what? I don't need to be technical enough for it.
I need to be a great leader who can build super smart people around me who are willing to explain things to me, teach me, um, allow me to ask the right questions and dig into an appro appropriate amount of detail to make sure that I am driving the business forward in an aggressive and, and also safe way. So yeah, You need to do a Ted Talk and you need to write a book, honey, man. No kidding.
No, it's, you're inspiring to me because it's just, it's just amazing, like your energy and, and just the way your brain works. It sounds like you've had some really great mentorship and bosses along the way that have really supported, like, gosh, we don't hear the, they supported me through raising twins story a lot. No, We don't.
I mean, I can go into a lot more, but I, I mean, I've had some exceptional mentors, sponsors, bosses, and not only had they, um, got me through my early years with my twins, and, um, but in addition, uh, I mean, my current boss is amazing. He helped get me through the loss of my husband. My husband passed away two years in the midst of a lot of leadership changes here.
And, um, and just really, uh, yeah, I'm, I'm still here and I'm still charging forward. And it got me through one of the most diff the most difficult time in my life, um, and allowed me the space to do what I needed to do, and, uh, but also welcomed me back and brought me back up. So I, I am really grateful for my leadership and my, my people, my tribe, um, my, my personal board of directors who have I feel like have surrounded me, you know?
And that's, um, yeah, it's really, uh, it, it, you know, I'm like, oh, I'm getting emotional. Oh, what a really, like, to have great people around you is, that's why I have my energy, because I have great people, um, ar around me, and, you know, and Carolyn, I'm so sorry to hear you went through that. Yeah.
Thank God you have the entourage around you to help you. We all need that. We really do.
Thank you. Thank you. I really appreciate that.
And, um, you know, and, and, you know, 35 years and most of that in tech, being a female is also, you know, quite a journey as well. And again, I, I feel myself lucky that I've had, uh, you know, amazing female sponsors around me, amazing male sponsors around me, people who, um, you know, who have just pushed me and, and flick that little imposter off my shoulder. And, uh, and I also think I've been, uh, look, I'll pat myself on the back to say that I think I choose my companies and my bosses very wisely.
And, uh, my choices along the way, and most recently being at Red Hat has been, uh, you know, one of the best decisions, career decisions I've made. I love the open source community. I'm sure it is amazing place to be a company that it's o an OA company built on open source like Red Hat.
You know, I'm, I'm a big open source band. That's why in my, in intro, it's always, Tracy does a lot with the Linux Foundation, but boy, open Source has taken a beating recently. You know, we're getting blamed for a lot of security issues, which probably is correct.
But, um, we've known this for quite some time, right? And maybe it's open source that's gonna get us out of this problem. Um, but I feel like there's a lot of stuff being written and we're not doing much with it.
Adoption of these security tools and for open source will be a challenge. Um, how do you guys talk to your community about, about security? How do you navigate that?
Yeah. Uh, I mean, it's a, it's a very important thing. But, you know, the thing with, with Red Hat is, you know, when you think about the op open source and, and we, you know, we live and breathe in the, in the open source, but it actually creates, I mean, our whole open source development model is taking these projects in the community, but bringing them and hardening them into enterprise supported products.
And, um, and that's part of the beauty of it. I mean, when there have been some of the bigger, larger vulnerabilities out, um, red Hat's been one of the first ones, and the Red Hat and the Red Hat community has been the first ones to raise their hand and say, we've identified it and we figured it out. Because I think that is the power of open source, is you are not only in a enterprise grade hardened product, but you have access to the community, um, that has that, that is using it along the way.
So, I mean, I think it's a benefit. I mean, I'm, I, I, I for sure have been, um, living and breathing it. And, and I, I also, you know, going back to the culture piece of it, I believe, you know, you can talk even more generically about security, and you can talk about security and the enterprise from a non-technical standpoint.
And I believe the open source, um, culture really starts to weed out these things as well. You know, when you are taking ideas and inputs from all different places, you're also getting people to raise their hand to say, I have a concern. And like at Red Hat, even internally, we have company-wide mailing lists where people frequently debate and discuss different topics, controversial topics, but the things that bubble up that, like we, as a leadership team, we're always monitoring it because some of the really, like, woo, okay, that's an interesting idea, or that's a really valid concern, or we might need to dig into that a little bit more.
That's open source too. And that's kind of the sa, you know, you talked about in your personal journey, being able to, to take a risk and staying, staying outside of a comfort zone, or just staying just a slightly outside of that comfort zone circle. Um, companies are doing that with open source, right?
There's, they may have, it may be pushing them a little bit, but I'm hoping where it pushes them, they can't get away with writing software without open source that, you know, that cat's out of the bag, it's not gonna happen. It would take a lot of coding. It would take a lot of work, and they wouldn't be able to keep up on the, what, what's new in AI without it.
So how do we as an open source community, make them feel okay about continuing to step out of that circle of comfort saying, okay, I'm only gonna use these particular packages, I'm not gonna try to use anymore. I know these are secured. Uh, how do we do that?
How do we bring open source back into conversation that people don't say, oh, there's a security issue with it from a bi from a broad community perspective. I know it's a big question, but Yeah. From a, I know, and I immediately go into just buy Red Hat, come on.
I'm like, no, I know you're trying to go broad on me. But that, I mean, but I think that is, it is understanding what is it that you're using it for? And is, are you accepting a level of risk in the open source, um, in the open source community that you are comfortable with?
What is, you know, a small startup company is different from a governmental agency or a banking, I mean, I, I think it depends on where you are in the continuum. But, but if you're one of these larger companies that's trying to stay, um, and keep yourself more secure than maybe your mom and paws need to be, that is where you need to still embrace the open source, but make sure it is enterprise wide grade, uh, open source, and that it's, it's hardened and has the security that you need necessary to make your regulators comfortable to make the, the various agencies comfortable. Um, but, but open source is, um, we've proven that it is secure.
Absolutely. And I, you know, I think more and more, um, some of the tooling that is being developed, open source tooling, by the way that's being developed, will, will help solve this problem. Um, and I'm hoping that, uh, we start embracing more and more through the DevOps, uh, you know, pipeline, adding more tooling and consuming the data and getting smart about it, because I love open source, and I would hate to see it go away, even though I don't think it's going away in any more than the mainframe ever went away.
And there's legacy open source out there, and there's new being written every single day. And we have to be outside of our comfort zone and start and consume it, because that's the only way we're gonna really build, um, innovation in this country is to accept it. Mm-hmm.
Right. It's just, I mean, it's, it's tied right there with ai. I mean, open source AI is, is an incredibly powerful tool.
It is incredibly powerful. That's just gonna unlock a ton of innovation, I think, unlike anything that we have seen before. What do they say?
This is, this is gonna unlock more than, than, you know, the invention of electricity. Uh, it really will. But, uh, I think, I believe that AI powered through open source is just gonna be exponential.
I would agree. And it's way beyond our comfort zone right now. Totally.
It is so beyond it, but we have to go there, right? We, we really do have to go there. Yeah.
And, and we have to, I mean, go beyond the, you know, what's gonna happen in six months. You don't, I mean, you just have to keep pushing the boundaries and pushing the boundaries and, and, and doing what's, what's, uh, you know what I was gonna say, what you're comfortable with, not what you're not comfortable with. But, but you, you can't, you can't, you no longer can do a year long roadmap.
A roadmap doesn't make any sense here. It's gotta be just fast innovation, iteration and learning. And again, I don't wanna, I don't wanna lose sight of the governance component of this, um, because it is, um, it, it's something left unchecked could be, could be quite scary.
So I know we're gonna, we probably we're gonna run out of time. Oh, we're good. We're good.
So tell us what's new? What, what's new and what's, what's happening at Red Hat that we might wanna know about or that you can share with us? Is there, you know, what's exciting?
We shouldn't tell anyone. Yeah. We won't tell anybody.
We wanna know what's exciting at Red Hat that the team is super, super jazzed about. Oh my goodness. Well, I mean, we were just, I'll tell you, we've been talking about it.
I, I think the thing that is coming out of our mouths in every single meeting, in every single investment decision, in every single, you know, just, um, interaction we have is, is around ai. And it is how do we, you know, bring our customers to the next level? And again, I'm looking at how do we bring ourselves to the next level, uh, but, but doing so in a way that, you know, other companies just haven't thought of.
I mean, we had just had something really cool, uh, a couple of months ago. We were looking at some of our models and, um, some of our LLMs and we actually had, uh, somebody from our team go and load up inclusive language, um, standards into our LLMs, right? And so you think about things like that, um, how just all of a sudden now, you know, something that we were a little bit nervous with about ai, now you load up into those standards, this is inclusive language, and, and all of a sudden it just changes the game a little bit.
Um, the other thing that I think is really cool is just skills development. And I think a lot about people and, uh, and where are we gonna go? And we talked about, we don't even know what's gonna happen in two months, right?
Six months a year. Well, we have to assume that every single role we have will not look the same in two years, in three years. So a lot of people talk about, well, does that mean these jobs can go away?
Well, what we believe is we really have to re-skill for, for these, um, for these shifts that are gonna happen. And so we've been creating a good bit of training curriculum and looking at, okay, what are the roles and the skills that we have today? What are the roles and the skills that we are going to, we anticipate that we're going to need?
And let's take that, create curriculum, create experiences, projects, um, innovation days to help people move along that continuum so that they will be ready when we get there, not if we get there. And I, I just think that's been really cool, something we're really excited about here. Um, so that, that's just, We have work with universities.
Mm-hmm. Very much so. Yeah.
It's, um, yeah, we have some local partnerships and, uh, so we work very closely with them. And, and I mean, our belief is you gotta go get the great university talent. Um, they're getting, you know, uh, not only are we importing talent from the universities, but we're partnering on a lot of projects with them while they're in university.
Um, and, and investing in that because, uh, again, that's where the innovation is coming from. It seems like the university system can be really slow to put together curriculums and get new classes offered. Yeah.
Uh, I think that's my biggest frustration with, with some of the students that are coming outta university is that they're, they're somewhat prepared, but they're not prepared for tomorrow. Yeah. Well, we are, we do, um, you know, we have various internship programs where we bring them in, we give them projects, but we, you know, we give them loose projects because what we're seeing out of these, um, you know, university minds is that they can approach a problem in a very different way than historically we probably would've thought.
So we do believe in the practical experience, but, you know, we've also been investing into those to make sure that it's not necessarily just a traditional classroom experience for this type of innovation. Yeah. I think we learned that with Seek versus OpenAI, right?
Mm-hmm. And was a couple of universities, the students had thought about it differently with the less money, and they were just motivated. Yeah.
And we're also trying to get, uh, you know, we are, we are partnering with, um, some of the local high schools and middle schools and, and trying to, you just ensure that we are, uh, getting the word out on the importance of STEM to, uh, the younger folks. So we, we often host like middle schoolers coming in here, and, you know, we'll do a little pitch on what is Red Hat. But what we will talk about a lot is just, um, what STEM roles look like in a high tech company.
And even if maybe you're not, you know, maybe you're not an engineer, well, still, there is a career path for you in stem. Um, and we show them what that could look like at a Red Hat. And so we break out into smaller groups.
What does a product manager look like? What does an engineer, what does a software developer look like? So that we're trying to also spark that excitement.
We give them projects to do that excitement, that sense of innovation at the very early age. And, you know, in addition to just getting, um, middle schoolers there, um, we, you know, we focus on underserved communities. Uh, we certainly wanna make sure that we're getting our young girls really excited about this and that.
We, I Was gonna say, tell me, reaching out in middle school that really does help young girls Yeah. Maybe redefine who they are and how they could participate in a, in a world where they believe it's dominated by men, which it is. I'm not, you know, we're not gonna deny it.
Yep, Yep. It is, it is dominated by men. Um, but, you know, that is, that is shifting.
And, um, and it is, it's shifting and it's, it's getting better. And the environments are becoming more inclusive. And I feel like, you know, voices are being heard.
And again, it's one of the, the, the great things that I love about where I am at Red Hat, because that is, we, we very much try to create that environment where you can show up as your authentic self and your voice can be heard, and you can use that to push Red Hat forward. I think men always show up with, with their authentic self. I don't think they know how not to, 'cause they're, they, they've been, they're allowed to.
I mean, they don't worry about putting on makeup at 14. Right. You know, they don't worry about getting facelifts at 55.
Right. They're totally okay about the, oh, they're worrying about that more and more, more than you think. Well, maybe so.
But women all, they're just not as vocal about it. They're not as vital. They attack amongst themselves like we do.
You know, you don't really know that the Botox is going in and, uh, come on, let's face it. It's, it's a thing. See That macera on there?
We you Do. I've seen the makeup closely, I think. Well, and there's a lot of painted nails, which I love.
I think it's fun. Um, back to the conversation about job elimination. I think when we're talking about these kids, especially college age, I think the incorporation of the AI is what's gonna help.
But it's also terrifying to these kids that they hear all this, you know, older folks saying, well, AI's gonna take all of our jobs, and then we wanna make sure we're encouraging them and saying, no, it's not, it's just gonna evolve what they look like. We just have to push that. 'cause even my kids, they're in their twenties, early thirties, and, you know, we've had that conversation, is AI gonna eliminate all these jobs of our friends and people we know?
And we just keep telling 'em, no, it's just gonna change what they look like. We still need humans. Yeah.
We still need humans and people who understand AI and, and yeah. And I, you know, I have two kids in college, and that's something that I, I'm like, you gotta understand digital skills. You need to understand critical thinking.
You need to understand the way the human mind works, right? Like, you need to understand these things because these are the important skills that will be necessary in a world going forward that will have ai, you know, it just, it, it looks different and you've gotta be prepared. And it's not just a college, it has to be lifelong learning.
Um, you have to be keeping yourself up on this all the time. And we all do. And, and, you know, you just don't think that your growth opportunity is learning in the job that you have today.
It's not, I mean, it is. Totally. Yeah.
Uh, so it's lifelong learning and, and pushing the boundaries of those skills that will always be needed. And we always need good critical thinking. So I'm the one who, who goes off the track here.
Um, before we finish, we've only got a few more minutes, I wanna hear about the Elizabeth Nash Foundation. Oh, Thank you so much for asking Matt. I didn't even see that one.
Um, So, Um, I mentioned I lost my husband, um, and, uh, he had cystic fibrosis. He ended up passing away of something else, but cystic fibrosis. And his sister also had cystic fibrosis and passed away.
And after she passed away back in 2003, we started up a nonprofit, um, foundation aimed at improving the lives of people with cystic fibrosis. And we, we kicked it off originally with, um, scholarships for people, uh, based on, you know, a whole variety of things. But people with cystic fibrosis, we, um, uh, invest in research, specific research for it.
And, um, most recently we're, we're taking an additional amount of scope where we've created, uh, a fellowship program. And what we're trying to do is, there have been so many medical innovations, uh, with cystic fibrosis that fortunately people are living and they're living longer lives. But what's happening is other things are coming up that they're, they're starting to lose their life to other things, but they're also aging.
You know, it's like new aging issues for people with cystic fibrosis that does not look the same as it does in a healthy body. So we've created a fellowship program where we are focusing on addressing the whole person with cystic fibrosis and making sure that as they age, they have the right healthcare and the right culture within the healthcare to make sure their needs are being addressed, and they can live a long, healthy, and meaningful life. That's awesome.
That's great. Thank you for sharing that. Um, I appreciate you asking.
It's a, it's been a labor of love, and I'm really proud of what we've been able to accomplish and, uh, yeah. More, more great things to come. And because you've been through it, you have the insight that's needed to be able to create a map of what can help people.
Yeah. Yeah. You really wanna take a very patient, you know, a, a person first, right?
You can start with the medical, or you can start with the, the researcher. You can start with this, but we're gonna try and start with the patient. Right.
Start with the human being first. It's, it's their experiences that are really driving our work. And from what you've told us today, I think it defines who you are.
I think you're very person focused. Absolutely. Thank you.
I try to be. Okay. As before we get cut off, is there a book recommendation that you can give to our audience?
Oh, um, so we have a little book club going on in my team here, and, um, the one, so we're just finished up, uh, think Again by Adam Grant, uh, for all your Adam Grant fans. It's just such a great book. I mean, we talked a lot about taking risks and thinking differently, and, uh, a great book highly recommended it if you haven't, haven't read it.
Um, the other one by Andrew McAfee, ma McAfee is, um, the Geek Way. So that's a really, really good one too. You asked for one, I gave you two, but Yeah.
Yeah. I gonna give You one for your book hub. You have what?
Uh, we do, it was a book that, I can't remember, one of our guests recommended it, but it's called The Logic of Failure. Oh, okay. It is really, really good.
It is. Um, one, you know, I read it, the, the, I don't remember who gave it to us. Might have been, might have been.
Was it? No, we always need to remember, we always forget. She said she read it more than once.
And, you know, I just got it on my phone and I read it pretty quickly, and then I was like, I gotta read this again. Because there's so much in it, in how the mind thinks. And so many good example examples of how the logic of failure works.
It's a really good one. But is like, based on the acknowledgement that failure isn't a bad thing, it's a good thing, and that, you know, but how you reactive, there's Really no, it's really, um, how we do, how we make decisions, how emotion can get involved in making decisions, how we don't follow the logic as far as we need to, to understand of successes at the end. Okay.
Okay. Kind of similar to the Geek Way, you know, some, some parallels there about Fastest Making Basket. Read The Geek Way though.
I'm gonna, I'm gonna read the, I'm gonna download it on Audible and listen to it this afternoon. Yeah. Write it.
This is our question at the end of every interview, so we have quite the book list. I should like compile it Tracy and, and write a, write who, who recommended it for us. But, um, I should put a blog out there.
I love it. Updated. Yeah, absolutely.
Well, thank you so much. This was just a wonderful, wonderful time. Thank you for Well, I know you're super busy and we appreciate you carving out this time to, to join us and, um, I know our audience is gonna love it.
So thank you again for being here. We really appreciate it. Thank you Both.
This was, uh, this was a lot of fun. Great conversation. I really appreciate it.
Well, we enjoyed having you. It's really insightful and everybody remember, stay out of your comfort zone. Exactly.
Thanks everybody for tuning into another episode of Techstrong Women. Stay tuned for lots more great programming on text drawing tv. We'll see you next time.
Thanks. Hey everyone, have we broken the internet again? You're watching Textron Gang.
Hi Everyone, it's Alan Shimel, and happy Monday to you all. I hope you all had a great weekend. I did.
You're watching Text and Gang, you know, uh, we've got a great week this week of Techstrong Gang. I'm excited. I've got a lot of stuff going on here at Techstrong.
There's a lot of stuff going on in the industry. We're gonna hear from some of our gang members what they've got going on, but there's a lot going on out there too. Can't wait to talk to you about it.
Let me introduce you to our gang for today. First of all, I don't know if he is also in DC going to the portrait, uh, gallery tour or back home in Austin. Guy Currier a rum and vi well VI principal analyst.
How are you guy? I'm real good. Thanks.
I'm actually on my way out in your direction, out heading out your direction. So I'm at the airport heading to Orlando for the Click Connect conference, so That's right. Very cool.
Very cool. On a weekend. Uh, it is.
Does Monday count Weekend? Well, it's Monday. Yeah, that's true.
It's gonna be another busy week on Click Connect. Very cool. Alright, moving from Guy, one of our newest gang members, but our, one of our cyber cyber sleuths, Teri Robinson.
Hey Terry, how are you? Hi, I'm great, uh, on this sort of rainy New York Day. Oh, it's rainy.
I'm sorry. That's okay. But, you know, well, I was gonna say, it's April showers May flowers, but it's may already isn, isn't It?
It's May. That's right. Looking for those flowers.
Yep. Good for you. Alrighty.
Joining us. Uh, I'm gonna assume he's home in Guitar Land, not Nashville. Denver.
Mitch Ashley, future VP DevOps analyst. Hey, Mitchell. How are you, man?
Doing good. Just working in the guitar store this day, you know, we'll open the doors and have some folks come in and do a little Selling coming up here. No, no, it's not the guitar store.
Well, look, man's gotta make a living. Um, you know. Yep.
And then he's still in DC it looks like from the looks of things. He's our Chief Content Officer, Mike Vizard, that has a distinct look of a hotel room, doesn't it? And it is distinctly a hotel room.
Yes. It's one of those, you know, westins, that book alike, no matter what city you're in, they all look the same. Yeah.
But they all have a great bed. Yeah, that's true. Right?
Um, yeah. Hey, Mike, how are you? I'm well.
I'm looking forward to taking the train home this afternoon. And, you know, I keep asking them to let me drive, but they keep saying no. Tell 'em your name's too, choo Charlie, I don't know if that might be a little over some of you, but, um, anyway, let's, let's move along.
So, is the internet broken again, Mike? Have has it, has our encryption failed? What's going on?
So there's this research paper coming outta China, and it's only a research paper, so I don't think we should freak out just yet, but it suggests that we can now predict the sequence or order of which prime numbers might come through. And that's kind of the key to how all of our encryption works. So this could be a significant problem.
Terry, I know you looked into it in your long time, uh, follower of all things cybersecurity. What's your take Here? Well, first I wanna say that I feel like everything I believe from childhood is slowly being dismantled.
Um, now it's, we're talking about prime numbers. Um, my, my, uh, recently departed math teacher, Sandra McCullough is probably, uh, looking down and with, um, so these researchers in, uh, in, uh, Hong Kong and, uh, in the United States published a paper. And basically what they said is prime numbers aren't as random as we thought that they, they were.
Um, and they actually also included sort of, um, a periodic table of primes, which is, uh, a lot like the chemistry periodic table. And, um, you can predict what the next prime is gonna be, and you can do it relatively quickly, which has the potential then to, to, uh, upend, um, encryption because that's behind, uh, you know, RSA and, and just about every other in encryption form that we have. So, um, that's why people are talking about it.
Um, whether or not it turns out to be a big, uh, blow up or not is, is definitely a question. Um, it's something to look at. And if it's not gonna be this, it's gonna be something else like quantum computing that's probably gonna, um, mess up, uh, uh, encryption as we know it today.
So, do I have this breakdown? I'm also looking at these new LLMs and they all have more advanced reasoning capabilities, and some of them can do math now. So rather than waiting for quantum, will somebody just take one of those and start applying it to predicting random numbers?
And we could be in a lot of trouble Together. We think. Oh, yeah, no, I mean, depending on who you talk to about this particular issue, that's, that's the case.
Some people are like, okay, maybe it's not gonna be so bad. And other people are going, well, in fact, with, um, you know, the large language models and everything, it's, it could be a lot faster than we thought. Um, without that, um, quantum is expected to sort of upend things within the next decade, I would say.
Um, it's gonna be quicker than that. Right. And Alan, as you well know, the bad guys are harvesting encrypted data now on the assumption that they're gonna crack it later.
So, you know, all our secrets are gonna be up there one way or another. They are. They already are.
They already are. Let, let's be real. But look, here, here's my take on this one.
Let's not run around yelling that the sky is falling and the internet is broken just yet. There, there's a, there's a long way away from saying I could predict what the next prime number is, and using an LLMI could predict the next prime number faster than humans can to actually using that to break, let's say an RSA algorithm. Encrypt encryption algorithm.
There's a lot, you know, using normal computers, not super duper crazy computers that maybe the NSA has to brute force some of these RSA certificates would take like hundreds of years. And so maybe using this technology, it only takes 35 years. Okay?
I'll live with 35 years. Quantum is much, is a, I think a much more deadlier, uh, threat to modern to present day encryption, because in quantum it has the promise of breaking it in a few minutes, right? And, but here's the good news.
Here's the good news for once NIST and, and, and mire and, and the industry appear to be out ahead of this, and we've got these post quantum algorithms that are already finding their way into DigiCert certificates, for instance, and some of the other certificates that are being used out there. And we're, we're making certificates that expire a lot faster, right? We're expiring our certificates now, not in 90 days or 180 days or a year, but we, we want 'em, they want us get down to expiring them every month.
So you're gonna be updating to the latest technology in your certificate encryptions. Now that information that, you know, like hash, you know, bundles of, of info every day that goes by, that information becomes less and less valuable because it's less and less current and less and less correct. So, you know, we've got a new American Post Pope piece me onto all of you.
Don't, don't worry just yet. I don't, I don't, I think this is a red Harry, You know what it, Terry, it reminds me of what you were saying about, you know, the thing, all the things you believed in, kind of being disproven. Take me back to math.
Math in high school and college where we looked up random numbers in a table and a book. They really just pseudo random. They weren't really random.
Um, but if we have a periodic table for prime numbers to be able to predict that, it's really, it doesn't take an AI system to do that once you've got those that table out, right? So this something widespread use, and, and I think, remember, weren't they calling it like crypto agile or some kind of a algorithm is what Yes. Is working on.
And of course there's also not just, um, quantum breaking current encryption, but also quantum encryption, which would be, you know, that much more difficult to break with anything. So I'm glad to hear, Alan, that you see this as a kind of a nen burger from the cybersecurity standpoint. I'm just blown away from just a mathematical standpoint from Mathematics.
This is Big news, this Foundational elements of mathematics. I I agree. Unpredic, All of our math teaches is Pattern And prime numbers.
Yep. Um, makes me think of Cold Fusion as a, as a non-expert and wonder if it's gonna be, you know, uh, disproved or refuted, you know, WW soon enough. I, I just, you know, we should take a moment, all of us to think e even if you not an expert in math, how fundamental the concept of how prime numbers work is going back centuries and there being a different way that they work, uh, could easily have much bigger imp implications across it, honestly, including in quantum, uh, that we couldn't predict right now.
So It'll be interesting. And I, I do agree, Terry. I think all of our math teachers are spinning, spinning in their graves over this, right?
I mean, it is like, I, you're shaking the foundation. We in trouble deep himself. I think we're in trouble deep if we're counting on the Pope to say a prayer for us at this point.
'cause usually that's the last thing that you say when you got Right, Right. When all else fails, turn, turn to God, tweet. So we have poping tweets, so, you know, tweet out, he tweet Out.
Well, I, I don't know. I'm, I'm sorry I took us down that path. I apologize.
Well, I, I was bringing religion into, I, I was gonna say too, I mean, it's also not like the industry is standing still on this. Um, you know, and just seeing where it spins out and the work that NIST is doing is, is, uh, you know, quite interesting and, you know, and ongoing and, and it kind of gets away from that single assumption that all of this has been, you know, based on before. And, and, uh, I think, you know, maybe there's gonna be some movement there that, that counters whatever might come from, um, from, uh, prime numbers not being random anymore.
But, um, yeah, we'll see. Um, it's, it's up in the air right now, but it's something to follow, right. And look closely at as we go forward.
I, I'm interested to see the mathematicians weigh in as well. Yeah, no, I'm, I'm look and research is good. I'm, you know what that, that's why it's important to fund research just for science cycle alone, right?
Because you don't know what you're going to turn up and what the commercial applications of it will be. Anyway, let's take a break here on Text Gang. Let's come back.
And we're talking gnats not the Washington Nationals, but you're watching Textron Gang. Hey folks. We're back.
And we're talking about another one of those instances where somebody decided they had open source regret maybe, and they were gonna try to take back their project. And there was a big kerfuffle over this. And then it turns out that the, it's still open source, but it's a slightly different, uh, flavor of it maybe, or it came to some agreement about the trademarks.
We'll get into the details, but it involves something called Nats, which as I understand it, is a framework for communications across clouds involving APIs and microservices. And it's a, from an outfit called, uh, Sonata. And, um, most people never heard of either one of these companies until this happened, Mitch.
So, you know, is this kind of like, you know, marketing in some level? Well, it, it's my third generation of Nats. Of course there's the Nats that fly around then network, ad headdress translation service, which is a networking thing that gives you an address that you can, don't, don't need to get from the internet.
And you know, as you said, you said it really well, you nailed it. You know, it's a communication substrate, uh, for talking across cloud, between microservices, kind of interservice communication. 9% of the world wouldn't know what it was even if you explained it to 'em.
'cause they don't need to know. And it's not that important. But, but it is important because, um, NATS has a, a lot of capabilities built into it and is used in, in a number of, uh, pieces of software.
It's also got like, uh, streaming capabilities, like a Kafka kind of solution. And so this keeps it in, uh, in the CNCF governance structure, the support, certification, all that kind of thing. Um, so it also, there was also really some trademark issues too that were coming up about that and how that, whether that can be transferred to the Linux Foundation, you know, all the lawyers, I guess the Pope got into it, and all the lawyers, you know, calmed down and, and agreed to whatever they agreed to so they could, so they could keep this open source.
But, but this is a great example of the flexibility in open source, right? So you got this company that, as Mike said, maybe had some open source remorse, right? My God, why did I release this open source?
I could have been making money on all these things, and we're not, you got the community and the LF and everyone up in arms about them looking to pull you, you once it, you know, it's like that butterfly leaving your hands once it's outta your, or Jonathan Livingston Seagull, for those of you who remember, once you set it free, if it comes back, it's yours. If it doesn't, it never was. And, and so it's out there now as, as there, there's a link to an article in the register.
And as usual, your, your register takes a snarky, snarky title for clickbait. They didn't tell 'em to fork off, but, but you are always free to fork an open. You wanna take, you wanna take an open source project and fork it and maybe close that off from that point forward changes you make.
But you, you do that. You, you get tried doing that, right? The half the security industry was doing it when Mitchell and I were doing still secure, right?
Under the covers, it was all Snort or Nessus or Nmap, or a combination thereof. It's the way of the world. There's nothing, nothing new here.
Move along. Uh, but we didn't have things like the Linux Foundation and the CNCF back then that would give these orphaned projects that they're, you know, commercial originators were looking to move away from or buried deep, um, a place to live. And, and that's one of the nice things about today's open source world, is you do have the lf, the Apache Foundation, the CNCF and others that give these, these projects a home that own the IP that do make sure that there will always, there is an open source version that is going to be continued to be developed, right?
Because right, like when Tenable stopped making an open source, Nessus, Nessus, what was it? 4, Mitch? Yep.
7, not an open source anyway. Right? I still feel like though, um, the, the bigger issue here is what's most, you know, salient, which is, um, I, I still feel like no, no vendor has really figured out how to profit from open source.
Let, let's divide open source standards or open standards, sorry, from open source software. We're talking about open source software here, things with licensing, so forth. Even open source software is licensing.
Um, I, I, you know, Cincinnati is basic complaint, right? Was, uh, this is our, the nobody's come to play with us, so we're doing everything for this. And, uh, why should we just give our engineering away for free?
Let's, we're gonna, we want to take it back. No, no one is, that's why it's so important, Mitch. I think that's why it's so important, because somehow it's unimportant enough for there to be a lot of contributors.
Meaning, meaning, uh, other vendors or, or institutions even, you know, public institutions. They're not investing in, you know, development talent to really get what's going on here with Nats. I don't know, NATS, I'm just saying, you know, so they're not investing in that, so they're not making contributions.
So Cincinnati is sitting there saying, well, you know, we, we've done all the investment. Why, why should, why should other people get to use it without us profiting from it? Well, Al and I went through this learning curve around open source, you know, believing, oh, many eyes, many contributors.
The real, the reality of it is in most open source project, there is one or just a handful, very small handful. There's six at most. Yeah.
Or even that, it's two or three oftentimes, maybe even one. Um, it doesn't mean they're not good project. They're great.
They can be great projects and widely used, but it does, that's one of the risks that companies are realizing now in, in open source, part of the assessment is who are the people maintaining it? Are they active? What happens if they Go away?
So through that time, it falls, it falls apart. Yep. Exactly.
But that, that's what I'm getting. So, so, so, I, I feel like it's obvious you have to invest in it anyway. You have to invest in creating the product.
If you're investing in creating the product and providing an open source, and you're the only one doing it, well, it's your business model to create this stuff in the first place. And it's your responsibility, whether it's proprietary to you or open source, it's still your responsibility to sell it, resell it, have a go to market model, have a marketing model, you know, all of that sort of thing. So my, my sense is that Cincinnati has, has fallen down in those areas.
They're not, they, if there's no market for it at all, okay, then there's no market for it at all. Whether it was open source or not. If there is a market for it, you can profit thereby.
And this, the, I think one of the original ideas in open source was, we're gonna, it's gonna be open source software and we're gonna, we're gonna profit off of services. Well, but that's not really, so, yeah. No, but, But you know what, I'm, I'm somewhat of an expert on open source business models, right?
So first of all, there have been successful open source companies. Of course, everyone always points to Red Hat. But, but beyond that, in today's modern software echo system, there's a number of ways of, of having a successful open source business model.
Number one, and probably most popular is, is the open core where the, the core of the project, of the product is in fact open. It may not have enterprise features, bonus features, the good stuff. And those are freemium premium add-ons, right?
So you could pursue an open core model and, and there are a lot of companies who have done that and made a lot of money. Very successful model. Secondly is, with the advent of SAS software, right?
Open source is not really known as being user friendly. You gotta set up your own server and everything else. A lot of open source companies are saying, Hey, you wanna take the the code and go, you know, do the binaries and set this up yourself.
Have at it good luck. You wanna just consume it as a service. You could use Jenkins as a service or this as a service, and that is open source software, but you're paying us to host it, maintain it, secure it, update it for you, and make sure everything's all good.
And there's a lot of companies who have done that with a SaaS model and, and have been very successful the pure, Hey, I'm gonna let you consume the open source, but I'm going to give you support and training. That's a failed model, right? That does Work.
And I would add, yeah, and I would add to the SaaS that it can be OnPrem, it could be internal SaaS, it can even not be SaaS. It could be exposed through APIs managed, yeah. Well, yeah.
Okay. Managed. Yeah.
Manage wherever it is. I agree with you, Alan. Um, but that makes you a lot more like a traditional vendor, traditional software, or traditional, uh, solution provider vendor.
And I know what you are. It's just a question of the price. Well, Alan, I gotta jump in with this.
You know, one, one of the things we've learned about open Source, you and I I think probably are like minds about this. I'm gonna quote the great philosopher, um, posthumously, George Michael, also a singer. You know, you gotta have faith.
You gotta have faith. There are, there are people who just believe in open source period and build companies with it. And guess what?
The user community figures that out. Those are the people we like. They really, truly believe it.
Seuss of the world. And there are people who, open source is a business model, and conditions change will take it or leave it. And those are the ones that tend to have not the true genuineness about it, that people pretty much sniff out and tell, and just wait for the crippled version and open source and the real version.
I gotta buy in an enterprise version or whatever. I'm not saying you can't do that, but I think most of the, most of the development community, uh, and even platform engineers and technical folks, you know, really the people who enjoy open source really believe in it. And they wanna work with companies that also are believers.
Gotta have faith. Thank you very much, Mitchell. Wham, Ashley.
And, and that's a, and that's another thing we can ask the Pope to pray for. Yes. Okay.
I, I didn't realize. Well, he guy says he tweets maybe he, he's into, you know, he's in open source too, maybe. I don't know.
You know, you hire, you have to close the show now. You gotta close it. Wake me up before you go.
Go. You may have to take the one of those guitars down off the wall and play if you want us to close it like that, my friend. Next Time.
Next time I, Alright. Hey, we're gonna take a break here on Textron Gang. Let's come back to our v uh, C block.
It's vexing VMware. You're watching Textron Gang. Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S.
Rogers, former director of the National Security Agency. And an outstanding lineup of industry experts as they navigate emerging threats. The core principles of crisis management and the evolution of CISO Leadership.
Register now for free. Hey guys, we're back and we're gonna revisit this whole adventure. That guy and I went on to visit Nutanix in DC this week.
And yesterday we talked about an alliance with Pure Storage, or actually last Friday. And now though, one of the things they were doing is touting themselves as an alternative to VMware. And we all know about the VMware licensing changes and the, a lot of, uh, folks are upset about that.
Let's just leave it at that for the moment. But Nutanix was out touting that they have now, you know, got some customers moving to their platform that includes small little construction companies to folks like Toshiba. The question though is, how viable is that option really?
Because like, even in Nutanix's case, they'll admit that there isn't that many IT administrators that are trained on it. They don't have as big a channel ecosystem and services provider partners. And you need all these things to kind of make that migration work.
And so, guy, I'm love to get your take on it, but almost every conference I go to now, somebody wants to beat up on VMware. And I'm like, okay, well that's just legitimate competition, but I can't get my finger around are these, you know, one-off examples of somebody doing something, or is this the start of a trend where we are gonna see these major migrations? I think it's probably a trend.
I think so. So first of all, can I ask this whole panel a question? Why did Broadcom buy VMware For, for market share?
I Can't f That. I mean, I think that that Broadcom has been tied up in the VMware ecosystem for a very long time, certainly before NSX because of the tight connections between VMware and V infrastructure and Broadcom, of course, especially for switching, um, the backbone of these virtualized environments. Uh, they've profited very much by that.
But I, I've still, I personally, I still don't get it. There are a lot of explanations out there, um, market share being one of them, and I don't fully understand that. How are they leveraging VMware, um, to gain market share elsewhere Or, yeah, no, I, I think Broadcom's broad and we, we saw this, you know, when Broadcom bought ca ca had amassed an amazing DevOps portfolio.
One of the best out there Broadcom's model, as best as I can tell, is they already have 499 of the global, of the Fortune 500. They got 1,998 of the global 2000 and and so forth. They're not necessarily looking for new customers.
They're looking to sell more stuff to their existing customers. They look at VMware and say, what percentage of the global 2000 and Fortune 500 are VMware customers? Very similar.
So that makes sense with these moves that, that they've made from the beginning. Thank you, Alan. Uh, there's certainly a favoring a reaving to the enterprise for the whole VMware portfolio.
Uh, and, uh, to be, you know, uh, to be honest, uh, my impression from last week at the Nutanix conference is that Nutanix in general is, is a lot more of, let's say, an intuitive operator user friendly sort of approach to virtualization. Their core, of course, was storage, virtualization, was hyper conversion infrastructure. But in the last four years, they have quite aggressively expanded outside of that into compute into containers.
Mitch, you, you, you wanted to add to this? Go ahead and Finish, but I got something to say about this. Go ahead.
Yeah. Okay. So, so they are becoming a more complete virtualization and frankly abstraction platform if you count containers into it.
I, um, a variation of what Alan said, I think you can, you can look at why did they buy 'em by looking at the actions that they took. Broadcom is the new ca ca was really a rollup getting more and more products. They've been that from almost the beginning.
And Broadcom has taken that very similar kind of tact. And VMware is a captive market. It's as much as we talk about moving off of VMware, it is difficult.
That is not, that was not for the, Ah, but I have news for you there, Mitch. No, no. Everyone, everyone claims they're making it easy.
And Nutanix's not the only one trying to nibble at the edges of v of this VMware thing. But here's an interesting fact. I found out companies that are moving off VMware are not necessarily moving off because the licensing three X was the primary driver.
They're moving off because they don't want to get, they want to move off lock-in, they want to go to the cloud, they want more options, and they don't get those options with VMware. And that's, that's a bigger reason to go into a Nutanix or any of the VMware bandits, Raiders, whatever AWS included, right? Is Hey, we're offering you more freedom.
And doesn't that something with George Michael too, Mitchell, freedom, I, I'm sure there's a wham quote we can find out. You know, wake up before you go, go. I think effectively though, a lot of those alternatives are not as conducive alternatives simply because of the nature of the applications being hosted.
I mean, Google put a one terabyte database into a container, I don't know, it's like five, six years ago now as a proof of concept, if nothing else. It doesn't mean that you wanna run something stateful on On a Container. No, but a Ws they all have VMware replacements guy.
Mm-hmm. They, or VMware. I'm not saying that.
I'm not saying they don't. I'm saying the operations of it are very different. Cloud ops very different from enterprise class enterprise.
And that's a, that, that is partially a cultural, but just largely, uh, like to Mike's point that he's made several times and, and introduced us with, we're talking about an entire system of training certification, ena, partner enablement, uh, o original equipment manufacturer, like the, the, the pc the equipment, vendor enablement and all that sort of stuff. So there's your answer that Really does not translate. So there's, that really doesn't but Guide to your first Yeah.
Question. There's your answer. Why did Broadcom by him?
I think you guys explained it really well. I don't want to try and re-explain it. No, no, I think you just did.
I think the other part, so I would po I would posit a theory here though. VMware may have miscalculated on how difficult it is to migrate. 'cause it is getting easier.
It's not easy. That's what I was, that's what I was saying. Yeah.
It's, And it Will, it'll, I can, there's nothing like a comet heading towards you for you to start thinking about, you know, uh, Ben a sending Ben Affleck in Bruce, I was Just gonna say Bruce will Space, Bruce, Ben Affleck and Steven Ty's door to waiting for me. Waiting for me. There we go.
That, so, so there's this motivation, there's this mo this, there's a very strong motivation that these shops never had before because they were, they, these were individuals who've invested their resumes in their career in that platform. And all of a sudden they're like, whoa. But I, but I think part of this though, And, and, and, and I should say Nutanix is being extremely aggressive in sales.
I've seen some of the programs that, fair enough. I'm just talking about Nutanix. I've been briefed on it.
They, they're really aggressive in because they, they, and they've been aggressive in engineering. They, they've, they've, they have invested heavily and intensely over the last 12 months in making those migrations Easier in many ways. So we do a series of, of webinars with AWS channel partners, and I, I personally hosted three or four of them where the whole gist of the webinar was here's how you move off VMware to AWS You've done them too, Mitch.
Everyone is trying to get at it. But here's the other thing. VMware is not a stationary target.
While Broadcom may be, you know, jacking up licensing, they're also honing VMware to be a better solution for those people who want what VMware has. And I think Guy and Mike both mentioned it, if you are already invested into that system, into that ecosystem And tanz, it's not like you're on in some ancient technology that's wasting away, they're maintaining it. And the, and the inertia around that is huge, just around the psychology of it.
I mean, people identify themselves as VMware administrators that, you know, they don't say I'm a generic administrator. They kind of attach themselves to VMware the same way DBAs used to attach themselves to Oracle, and it took years kind of Cisco Yeah. To cna.
So, so, so let me, let me, let me explain then to people who probably don't need this explanation, what VMware really did, or I should say what Broadcom really did. It's not the changes in licensing, it's not any of that other sort of stuff. The effect of what they did a year plus ago was to p**s people off, to p**s people off by making big changes.
That, that actually looked a lot worse in some ways than they were. But also with a restructuring with like, VMware had so many pet projects and they were pet to their buyers and their customers. So I, to me, that's what, that's what the industry is reacting to and smarting from.
It's, it's, it's again, like we always keep coming back to culture. They p**s them off and they are, they are. And they p**s partners off too.
They made every single partner real Thought. I, I think that was a a a, uh, they didn't do that blindly. It was a calculated move.
You know, the old saying better to be p****d off and p****d on. And they, you know, they made a decision. What percentage of that business would they be willing to lose by tripling the license and honing in on their, on the customer base that they want.
You know what, we could sit here and speculate, but, but who's the Broadcom? CEO Mitch, what's his name? HH Hoan.
H Hoan. Hoan. Htan.
And, and, and I, he's, no, I really appreciate what you're, I really Well that's, I really appreciate what you, what you're saying, Alan. 'cause last week I was saying to Mike, when I don't understand what one of these folks does, I always know that there's something I'm miss, or oh, there's almost always something I'm missing that I'm not seeing. And you're helping to explain that because it, it has come off to me very like, off and, and, and, but I know that, that Haan and the, the leaders around him and that organization are super smart, very strategic.
I'm Sure they had it figured out to the fourth decimal point. Don't, maybe not to the prime number. Yeah.
Anyway, so what you're saying, what you're saying guys, is you don't wanna miss a thing. Right? Exactly.
Arm the peanut, the peanut gallery record company. Alright, that's it. I'm, I'm gonna do some studying before the next game game.
Oh my God. And you're gonna hear from me, Mitch Pop music for 500. Alex, I'm, I'm gonna be trailing the Barry Manalow catalog.
That's what I'm gonna look at. Guy will take wham for 200. Alright.
Um, remember to answer in the form of a question, guys. We gotta wrap it up. We gotta wrap it up.
For those of you traveling safe travels. For those of you out there, stay tuned. We've got, we got Techstrong TV coming at you right after this, so stay tuned for that.
Also, a quick reminder, if you're catching this, you can now watch us on our OTT channel where we're being updated every day. You could get OTT on Apple devices, Android devices, Roku, Amazon Fire, and Apple tv, text, drunk tv. Check it out.
Until next, until tomorrow, I'm Alan Shema. We're out. Hey, everyone, welcome back here to another Techstrong TV interview.
My next guest, I'm pleased to introduce you to her is Vagi Koani. Vagi Koani. I hope I got that right.
Vagi, welcome to Text Drunk tv. It's great to have you on here. Hey, Alan.
Um, uh, great to be here. Uh, thank you for inviting me for the, uh, discussion. Absolutely.
So, SGE, you are the president of Enterprise Services and Train AI in RWS. First of all, let's start with RWS. A lot of people in our audience may not know RWS tell us.
Absolutely. Um, RWS is a global company, and we are a leading provider of, uh, technology enabled language content and intellectual property services. Um, uh, for the past 20 years or so, we have been building our own AI solutions as well as helping a lot of our customers explore, build and use, um, multilingual AI applications.
So essentially we are a tech enabled language organization, and, uh, we, we have been doing AI for long and helping our customers, um, um, unlock global understanding. In fact, that is our, um, uh, purpose, um, as an organization. Very cool.
What's the website, by the way? com. Great.
All right. So train ai. Look, everything is AI today.
Everything, ai, that is AI agent ai. Why don't we start off with what exactly is train ai? Absolutely.
Um, train AI is one of the newest businesses that we are building within RWS, um, essentially to help, um, uh, support AI builders. Um, so what we do in train AI practice is to, um, uh, one, um, obviously train the data, uh, which is required to build ai. So we have multiple service offerings that we, uh, uh, provide to our customers, which involves, uh, data collection, data annotation, as well as like validation of data.
With advent of gen ai, there's a lot of services that we offer in terms of, uh, validation of, uh, content, which is coming out of, uh, um, you know, LMS and Gen I, as well as, uh, test of, um, we can launch an application. So we test for vulnerability. We test for hallucinations in the data.
So, uh, to summarize in a, a core sense, the services that we provide helps build AI applications and essentially put out quality output. So all the work that's done in prepping the data, uh, is what we offer as a part of our, uh, training services. Excellent.
I love it. Now, you guys recently did a, uh, a study with some benchmarks on this new train, A-I-L-L-M, synthetic data generation. And, uh, well, I don't know more about it than that.
Why don't you tell, tell us what, you know, what was this about and maybe, maybe what some of the findings were? Absolutely, absolutely. So we decided to run a very comprehensive, um, study to benchmark some of the LMS and their behavior to data.
Uh, so there were two, uh, objectives that we had in mind when we started with the study. Uh, we realized that, um, uh, the leading LLM developers, which includes OpenAI, Google, and, uh, and the likes, um, are training a lot of their l LMS on the public information. And of course, to fine tune the models to specific domains or specific, uh, use cases, they need to rely on synthetic data, which essentially is generated by L lms.
So one of the objectives for us was to, uh, see, hey, can we generate synthetic data using the L lms? And as a part of the study, we also wanted to benchmark and, for example, uh, qualify, um, uh, the LMS on, um, hey, uh, how are they, uh, performing in terms of reliability, in terms of their quality scores, in terms of their natural language, um, uh, quality, et cetera. So, so the goal was to generate synthetic data using popular L lms as well as to benchmark, uh, the L LMS in terms of various parameters.
So that was the purpose of the study. And, um, um, uh, let me explain a bit in terms of like how we designed it and what exactly we ended up doing. Um, so we decided to test around nine popular l LMS for the study, which included, uh, GPT-4, Gemini Probe, menstrual Llama, Jamba, and cla.
So there's a bunch of them that we, uh, picked up, in fact, the top performing LMS in the market. Uh, we decided to test out, um, around six task sequences, which includes sentence generation. So again, that was put into like simple, very domain specific entity rich conversations that you would have with the LLM.
Uh, we also looked at like, um, uh, text normalization, translation, et cetera. So it, it was a sequence of tasks that we wanted to test out and, uh, benchmark the study. Again, we picked out eight different languages to run the study, which, um, included the popular languages like, uh, English and French, and also, uh, some complex languages like Tamil, um, Kenya, Rwanda, which is an African language, Tagalog, uh, simplified Chinese, et cetera.
So it was a set of, uh, a different languages that we used. And then, um, we wanted to evaluate these, um, outputs from LLN. So we decided to pick, um, expert linguists per language, uh, who would be rating the study on grammar naturalness, um, uh, kind of compliance, um, of the instructions and variability of code put that as generated.
So that was the, uh, core, um, uh, study design principles that we followed. And, uh, we, um, ended up, um, uh, kind of, um, um, testing out multiple performance dimensions, um, which included language proficiency, obviously, to test out, like how a language, um, like an English and, uh, French performs versus so some more complex language, um, like a Tamil or, um, a Tagalog, right? Um, we looked at, um, how do these lms, um, um, follow instruction adherence in terms of like generation of sentences.
Obviously we were talking about synthetic data generation. So we gave instructions and we looked at like what kind of, um, uh, inter instruction adherences followed by these elements, how many words are, uh, created, uh, per sentence, for example. So that was another dimension.
We also tested out creativity, which is like output variability. Is it just a textbook, uh, reputation of some data, or based on our prompting it, the LMS are capable of generating something which is more conversational, more prone to, um, uh, human output. Um, another key parameter or speed.
So which LLM performed, uh, fast compared to, um, the, the others. And also there was a cost aspect, right? Uh, in, um, uh, in technical terms we, uh, call it as like tokenized efficiency, how fast, uh, and, um, how many tokens are used in this particular, um, uh, study itself.
So these were like around five dimensions. We tested out, uh, on all these nine LMS that we picked up. Um, so we had some interesting, um, uh, findings from, um, uh, the study itself, right?
Um, for example, we found, um, uh, strengths and weaknesses on almost all of these lms, um, uh, on these five dimensions. Uh, for example, a Claude Sonnet performed very well on most languages, uh, kind of like best instruction compliance, right? However, it took up a lot of, um, tokens, uh, to generate this particular data, especially in some languages like, uh, Tamil.
And it was also slow. Um, another example would be, um, Gemini Pro, which was like very creative in, um, strong in, um, uh, languages, like a Polish or Chinese tokenization. But actually flame failed in a language like Tamil.
Um, Lama for example, performed, uh, fairly well on some of the languages, but was extremely, uh, slow. Um, mytral, which is like a French company, obviously performed very well on the French language with a decent speed, but, uh, did not work well on the other languages. So it was kind of like a combination of strengths and weaknesses that we found on all of these, um, l lms.
And, um, obviously one performed well versus the another, right? Um, some of the challenges, um, uh, I would like to call out this, see, this is like, kind of like a very fixed scope study. So we cannot, uh, say that, hey, uh, this can be taken and applied to another a hundred, uh, languages per se.
So it, it was, uh, a limited scope of like, um, um, nine different languages. Of course, we had indicated references in terms of complexity and things. Um, so that's a limitation I would like to call out.
Sure. And also, the human ratings introduce objectivity. So it's more about like, Hey, how are human thinks versus a, um, machine or like, um, uh, system things, right?
Um, so those are things. And, uh, if, if you have to, um, uh, ask me about a final takeaway, uh, our finding is of course, like not one LLM is like a one size fits all solution, depending on, uh, language needs or like specific use case requirements. Obviously we have ranked, um, uh, the performance of each of these, um, uh, language models, and we could pick and choose them based on like what use cases we are trying to implement.
So that's, that's an, um, uh, final takeaway if I have to summarize it. That was fantastic. So, of course, you know, we don't have charts, we don't have graphs in front of us.
People are listening to you and they're trying to maybe take notes, but it, I am assuming the study report is available on the RWS website. That's correct. Um, Holland, um, so we have two versions of the report.
There is an exec version, which is kind of a short summary of the study itself, which is on the train eye site on the website. And, uh, we also have a comprehensive report, which is like a hundred plus pages in terms of like details and how exactly it was implemented. Prompts, which is more for like the developers technology folks.
So both the versions are available if anybody's interested in, uh, you know, exploring further, You know, in today's world, everyone wants the exec summary, but there are people out there who do like to get into the, the guts of it. com, should they, is it right off that first page? Is there something else?
Um, there is a train AI section under train AI section. They could find it, or I could even provide a link, right? So, so we have, uh, yeah, If you could, maybe we'll put the link in when this airs.
We'll put it in the notes. com, go to the train AI section, and within the train AI section, you will find a link to this, uh, benchmark study. Yep.
Fantastic. Versai, thank you for coming on and telling us about this. Appreciate it.
Um, continued success. Keep, you know, we, we are, we, we've been, you know, AI has taken over our thoughts for the last two, two and a half years, but it's important to remember, we're just at the beginning of the beginning here, right? We're not even at the end of the beginning.
Um, so I'm sure as things, it's fluid, as things move forward, we'll hear more and find out and learn more. Keep doing what you're doing. Thanks for being on Techstrong tv.
Thank you, Alan. Thank you for the opportunity and, um, being a technologist, being, um, um, um, AI expert. I do believe that, uh, there's a lot more to come and, uh, exciting time Ly, it's a great time.
It's a great time to be in this. Yeah. All righty.
We're gonna take a break here on Text Trunk tv. We're gonna be back with more coverage in just a moment. Welcome back to Text on tv.
I'm Lisa Martin, live from RSAC at Moscone West in San Francisco. We're gonna be talking all things security all the way through Thursday. Some great content we've already filmed.
Hopefully you've been watching more great content coming your way. My next guest is Naomi Buckwalter. She's the Senior Director of product Security at Contrast Security.
Naomi, it's great to have you on Textron. Hi. It's Good to be Here.
Thank you for joining me. I'm so excited. How are you today?
I'm excellent. Awesome. My feet don't hurt yet.
It's day one. That's why I'm wearing. And I hope that is true for the rest of it.
Me too. Fantastic. That's one thing about conferences.
You can guarantee a ton of steps and sore feet And no lines in the women's room. That's true. Yeah, That is true.
That's, that's one plus for us girls. So I love the tagline at Contrast Security. You can't stop what you can't see.
Tell the audience a little bit about contrast security. What is it that you guys are solving for customers? Oh, interesting.
Well, if I could give you an elevator pitch. Yes. We do application security in production.
That's the easiest way I can explain it. I love that. Right?
It's clean, it's so easy to understand. Yeah. Well, if you think about it, we have other things in security production, things like we have our CrowdStrike that's running in production boxes.
Right? Okay. Like, we have different agents that run in production.
If you think about the vendor space, there's not a ton of application security happening in production, in runtime. A lot of it's before the runtime happens. So you've got your static scans, your SCAs, all the scans that happen in QA and Dev and all the things that aren't actually production.
Yeah. And you have to wonder why it's, it's kind of weird. It's weird.
Yeah. Well you were saying, you know, that doing AppSec in production isn't crazy. It's It's smart.
It's so smart. Why aren't more folks, Did you say that or did I say that? I Got that from, oh, Okay.
You so smart. You're smart. Actually.
It's smart because, but why aren't folks doing? Because it's where behavior happens. It's where the users are, it's where the attacks are.
Why aren't we doing more security where the bad stuff is happening? Right. Why do we assume we're testing for all the cases prior to releasing the thing in production?
Yeah. Well, I can tell you why. I know it's smart.
We just said it. You said it. But I think it's because people are scared of doing AppSec in production.
I think just tech, in the past we've had downtime is an issue. Your company is like, no, we need to have this uptime. 999, whatever.
Right? To five nine. Thank you.
And I think it's put us back a lot. A lot. So if you think about some of the bigger breaches in the past, it really comes down to you probably just had this old server running with an unpatched thing for the longest time and you were afraid of taking it offline off production.
Right. Just to fix it and then put it back up. Yeah.
Because your business is like, no, we need all the uptime, we need all the revenue. And it, and it becomes this problem because you don't have the protections that you actually need in production. Yeah.
Well, It's a double-edged sword and it's, it's like nobody wants to be the next headline for a breach. So it makes sense. Right?
I know. I mean, the brand reputation, the churn that happens, nobody wants to be that. I mean, in these, in this day and age security attacks aren't, is it gonna happen to us?
It's when, oh, it's happening Now. It's how Often it's happening. It's now what is the cost?
It's gonna cost my business. Right. Right.
So That alone you think would, would make enough sense for them to put apps like in production Production. But I didn't even get to the biggest part. It's because we don't have the insight that we need in production in our applications.
We are really good as an industry of getting our network traffic understood. All the things that are happening on our hosts. Understood.
We know all the things that are going on because we have observation, we have sensors in those areas. Yeah. What we don't have are those same sensors happening in our applications at Runtime in production.
And now we're trying to say as a company, I think it's time, it's okay to do AppSec in production. It's okay guys. Like I almost feel like here at RSA would be our, like our unveiling.
Yeah. Is that an, is that a word? Yeah.
Or unveiling. Like our unboxing for YouTubers. Yeah.
Yeah. So it would be our way of saying to the community, like, it's time shift left probably has failed. Yeah.
Well, how much of what you're doing at Contrast is really education and making these folks aware that it's about, it's time. And this is why that old playbook mm-hmm. Has to be thrown out because nobody wants to be the Next headline.
Absolutely. And, and it's, it's a little like pulling teeth. Yeah.
If we had like an interpretive dance, maybe people would probably understand it more because it's, sometimes we're like, what are you talking about? I had a dinner yesterday with somebody at a different company, someone who does static scanning, and it's like when I told him we should do AppSec in production, it's like, I stabbed his child. Like his reaction to that was really just like, you could just tell his face.
I was like, I'm sorry. Do I need to apologize right now? Yeah.
Like he was just so insulted the fact that even said that because it's so ingrained, it's cultural in us. Right. So it's Behavioral.
Exactly. And that's Why Hard to change why, but why You're right. Right.
Our critical thinking turns off whenever we are thrown another framework or another way of doing something. Oh, and everyone does it this way. Think of the thousands of other people Here.
So I'm gonna follow that line That you just Absolutely. Yep. It's a bias that is not well understood by me, just because I could see the issues.
And most of us in AppSec actually do, and here's another problem is security. People traditionally don't have the best grasp of applications anyway. Okay.
So what they do is, or what we do is we kind of just say, Hey, we're gonna let the developers take care of it. We're gonna do our scans, we're gonna give them the issues, and then they're just gonna magically fix it. That's not what the developers wanna do.
Trust me. They wanna build stuff fast. Yes.
They wanna make money. They wanna go home and build cool s**t. At the end of the day.
I am sorry. They build cool s**t. Yep.
And then call it a day. They see security people and they always have as a gate. Yeah.
A gate As a detractor to what they're trying to do as a, you can can't do that. Exactly. Yeah.
So what we are now saying is maybe that approach has failed us because think of all the issues that are still happening. OAS top 10 hasn't changed in like two decades. Right.
How embarrassing. For us, now we're saying application security can be done without the developers. We don't need them anymore.
Okay. Yeah. And I know that sounds really like, who heck are you Karen?
Yeah, yeah, yeah. But we haven't given this a shot enough to say that. Maybe it won't work.
Maybe it will. Yeah. Why not?
Right? So you're in effect enabling the optimal developer experience. 'cause you're pulling this out of their, that's another of hands.
And the AppSec folks can take their responsibility on in production. Amazing. Do you have a newsletter?
I wanna sign up for your newsletter. That was really good. Yes, you do.
Yeah. So, so where are you talk, who are you selling to? Is it the developers?
Is it the security folks? Is it both? Is it the application owners?
Oh my gosh. Well, everyone and anyone who will write a check. But I will say we are targeting a new audience and it's our SOC people, our security operations folks.
Yeah. So what we're trying to sell them is more insight into the applications that are on their networks. Like all the applications and hosts that are on the machines that you care about.
Run processes and things and accept traffic and do stuff with that traffic in your host that you should really know about. Right. So we're giving them observations, more data, more insight into their application layer, into their APIs that they don't already have.
Right. And I think our soc, what we're hearing from the fields is that, wow, this is great. Like before it was just another network packet.
Like, I don't know what this is doing now. It's wow. It's not only do I know where this packet is going, what route is hitting, what that route is doing, what it's executing in the host, or what data point is hitting on the backend.
Right. Like now that we have all that insight, we can do something about it. If it's an application attack, we can block it.
Because Contrast does that really well. Yeah. If it's a vulnerability that if out there, maybe we could tell the developers how to fix it.
And we do that too. Not only do we block the The attack, we can tell you where the vulnerability is. We can patch it.
Right. Like we have ai, how to fix, like we have all these cool tools that can just tell you how to fix it. Yeah.
It's really cool. Well That, that application detection and response technologies, observability. Mm-hmm.
Our game changing for organizations. Yes. It's like the tagline that I like, you can't stop what you can't see.
You need to, they need to have that visibility. Yeah, absolutely. But also in a sense, getting outta the way of the developers, letting them have the optimal developer experience that they want.
Yes. That they expect. Yes.
But providing that visibility so the blinders are off. Absolutely. And you're letting them do their job better.
Yes. And you're doing your job better too, as security people. Yeah.
Security people can do application security. I know it's sometimes hard because we have to keep up with your technology. Yeah.
But once we do, we can show them we're on the same team. Right. And then now you're building relationships.
Now you're building culture on your team. And trust. And trust.
And that is a hundred percent Yeah. What you need when you're working with developers. Like Yep.
I had conversations, we were like, why are we doing it with you guys? We can ruin your life if we want to. Like, that is an adversarial relationship.
Wow. Right. This is not a person that I worked with, but I was just talking to.
They're like, we can ruin security people's lives if we want to. Like why are they so us? Right.
Wow. Power. Right?
Mm. Wow. What's your favorite customer story of contrast that you set?
You think this just perfectly shines a spotlight on what we do well and why we're doing it? Well it's funny 'cause I'm a security practitioner. I'm my favorite customer.
I actually use contrast every single day. Awesome. Drinking Your own Champagne.
Thank you. Oh, not the dog food thing. No.
Champagne one. I Like the champagne. I elevated it.
Thank you. It's so much better. Well, so I'm a secure, I'm a security practitioner.
I would not be working for a security vendor if I did not deeply believe in our product. Yeah. I am not even saying that lightly.
Like I understand how cringe it is to be here. I'm sorry. RSAI love you.
But it is cringe. And I will say it's just like LinkedIn. It's like, why are you so cringe?
Why do you have to do this Cringe. It's security vendors doing too much and it's not actually helping do security. So me as a security practitioner really appreciates a tool like contrast.
'cause it makes my job so much easier. I don't have to do a scan and be like, here's 500, um, 500 vulnerabilities. That's a static and I haven't even validated each one.
Good luck with that developer. It's like I can give our developers actual vulnerabilities, actual vulnerable routes, things that have been exercised in our applications, which means endpoints that have been hit Yeah. In production because we know this is a route that has been used and here's a vulnerability, here's an attack that happened and then we could do something about it immediately.
I don't have to wait for the patch. Right. I can do something in our tool.
Contrast can be like, okay, we're gonna gonna block this for now and then gives us some time to patch on the developer side. Yeah. And think about Log for Shell.
It was the same way. Yeah. We blocked log for Shell.
Okay. Out of the box before anyone even knew Log for Shell was a thing. Wow.
And now it buys the developer's time. Yeah. Right?
Because you're like, yeah, you're using old versions of Log for J that are vulnerable to log for. Shell go ahead and fix this thing. Right.
And by the way, we have contrast on the other side acting as that last gate. Thank God we have them. You know, you Should be a developer's.
BFF. I Already am Lisa, I dunno what you're Talking about. Of course.
You're Naomi, it's been such a pleasure having you on text, on tv. Thank you for really explaining what you guys are doing so well. Why apps suck in production is smart.
We appreciate your insights and your candor as well. Appreciate that. For Naomi Buckwalter, I'm Lisa Martin.
You're watching Text on TV live from RSAC. We'll join you again after a lunch break with our next guest. So stick around.
Hey everybody. Welcome. Welcome back to RSAC, the techron coverage from techron tv.
I'm Mitch Ashley, uh, Futurum leading the analyst practice for application development, DevOps, application security, all kinds of good stuff. I'm joined by what, what I would call a good friend. Brian and I have gotten to know each other, uh, for a long time, talking usually at these kind of events.
Yeah. Most of the time. We're about half the time we're on camera.
It seems we Just did this, Didn't we? We did. I think what we should just pick off from wherever we were last time.
So Brian Fox, introduce yourself. Tell us you know, your background and hi Sonotype. Sure.
I'm, uh, Brian Fox, co-founder and the CTO at Sonotype. Um, I'm also on the open SSF governing board and the FENOs governing board and, uh, Singapore Monetary Authority Cyber Board where I was last week, uh, talking about a lot of this stuff. So yeah, that's, that's me.
Ba long background and open source. You certainly do. Yeah.
And distinguished and a lot of contributions, which thank you. Definitely appreciate it. Um, yeah, I, lots of things we could talk about.
You know, I'll hold off the AI word if we want to for the moment, but, you know, one of, one of my senses in kind of knowing that we've gone through this, uh, before, right? Adoption of the cloud, adoption of rolling out things in Kubernete and, uh, and Covid, ID um, it's always kind of what and what do we do about security survey after the fact? And hopefully we're not doing that again, but it kind of feels like in a way we are, is is security sort of the, uh, secondary thing.
It's not off the radar, but it's let's vibe code, let's create agents, let's do all these things and okay, how are we gonna secure it again? Um, JP Morgan Chase CISO issued a letter saying, Hey, the industry needs to step up and do more about security. If you were gonna write that or you were gonna give that talk, what do you think we need to be doing?
Yeah, I mean, I, I feel like I could have written the same letter. I feel like it's the same thing. I've, that was my first A Reaction time.
Yeah. Um, you know, I've kind of gone through this, uh, this cyclical thing, you know, like I, I, I felt like 15 years ago the problem was awareness. If we only educated people, they would do better.
And that's true to a point. But I think over, over the last, you know, like I said, 15 years or so, the industry has, has gotten better, but not better enough as we've seen with all of the high profile attacks. You know, SolarWinds, log four J, you know, all the malicious attacks that we're seeing these days.
Um, you know, and so in response we saw, um, you know, regulators worldwide stepping in and trying to put their thumb on the scale. And, you know, I've kind of been a champion of that over the last handful of years and trying to, to, to work to massage that and make sure that those, those policies are effective and not punitive. Um, you know, we we're potentially seeing a, a backing away from that.
Um, you know, that that momentum, which is a little frustrating, at least here on the US side, you know, Europe, India, Singapore, they're still pushing hard on that. Um, and I, and I think that that's good. Um, you know, and so, you know, the open letter from JPMC is sort of, you know, calling on the industry to do better.
Um, you know, my response to that is like, that's great also, um, you know, the industry needs to be able to kind of put their money where their mouth is, you know, the, the, the vendors to these large banks will do better if the banks demand it. Mm-hmm. And so it's, you know, asking them to do better.
I feel like that's what we've been trying to do forever. You know, so there's two ways you can move that needle. The regulators can force it.
The, the large consumers, banks in this instance can also force it. You know, that was sort of the process that the US government was taking about sort of mandating SBOs, um, mandating, uh, attestations, things like that. If these large software acquirers, non-government ones can do it too.
If they start demanding the same things, I think it'll have the same effect. But they have to band together and do it, and they have to be consistent about it. Yeah.
I almost wonder in part if that letter might have been issued because of the change in direction with cisa. You know, we want you to focus on securing, you know, a national infrastructure less, I would describe it as less taking a leadership role. I won't put you in a position, it's describing it, but it, it's almost like, okay, now we have to step up in a different way.
The, the large consumers of technology is certainly one approach. Mm-hmm. To that.
Um, any, any other thoughts of ways we might collaborate, work together to strengthen security as a community? I think I, I think it's those two things that I said. Either the, the, the government steps into force it, which can often be heavy handed.
Uh, or, or, you know, ultimately consumers have to demand it. And, and in this instance, I'm not talking about end user consumers. I'm talking about, you know, the, the large enterprises that are the consumers of software.
If, if they need to demand it as well, only then will the economics force businesses to prioritize these things in the right way. Uh, you know, I, you and I have spoken about software liability reform and things like that, you know, and, and that's part of it because until we can rebalance the, the economics so that, uh, losing data costs more than just buying people, uh, their 10th subscription to credit monitoring, until those economics are, are balanced, that we won't see the behaviors change. Right.
And so there's many ways to balance them, like, like we've talked about. Mm-hmm. So I think, I think we need to see that we're not seeing it enough.
And certainly, you know, with the, the, the land grab gold rush, whatever metaphor you want around ai, you know, it's, uh, like, like you touched on in the beginning is kind of, we're seeing a backslide, I think, in that too. Yeah. I remember sense that of like, you know, we need to get ahead, you know, every day we're, we're falling behind faster with AI because of the pace that it, it's moving.
Yeah. So, so speaking of ai, someone mentioned at a, at a talk that I was at, uh, well, we won't do anything about security and AI until the next, for the first big event happens, sort of the, the target data breach, the log four j the, you could pick out whatever kind of milestone occurrence that got everybody's attention. You could also argue, well, that could happen very much faster if with the pace that AI is moving and how much people are doing vibe coding or agents are using AI and their tools, but not securing it properly.
Do you, you follow that too? Is, are we kind of desensitized to the next big event gonna cause anything to change? There's definitely that element.
I mean, I think, um, you know, the, the, the, the desire to keep up and the race for AI is causing people to grab the latest things, you know, without vetting them. Right? And so it's like, oh, there's a new model out on hugging faces, let me grab it and, and give it a shot.
And so these are the exact behaviors that lead to dropping of the guard that, that the malicious actors look for, right? So there's already been cases of, of, uh, copies of models that are put out there that do nefarious things. Now the, the, the danger with the AI is that, you know, you tend to want to feed it information.
So it's a little bit different than just a piece of software that you're running that may or may not have access to The role of data in it. Right. May, may or may not have access to lots, lots of your data depending on what you're doing.
But that's like, that's the main point of you of the ai. People want to grab these models and kind of feed it all of their data. Well, if that's an untrustworthy piece of software that's hoovering all that data and sending it somewhere, it's even more dangerous than, than what we've seen.
And so we have this interesting collision of people are, you know, dropping their guard trying to go fast, trying to new the, use the new and novel thing and not really thinking through all the implications. Mm-hmm. You know, I, one of the things I've been thinking about too is one of the differences with AI is since it's it's code driven, but it's driven by prompt and, and so there's so many more ways of injecting prompts or AI changing its own prompts.
Yeah. I mean, you've got this whole vector in there that, uh, can be interjected not just by users, but by code and also other AI systems. So in some ways, we almost need better internal security within AI systems.
Not just good guardrails, but what happens when AI is generating Yeah. New and novel things, if you Will. I mean, the, the power of the AI systems comes from the fact that they're not exactly deterministic.
Mm-hmm. That's why they're so useful. Um, they, they, they can approximate novel thought, right?
Hmm. Um, but that also makes it impossible to actually thoroughly test all of the things. So where does that leave you?
It leaves you in a world of having to depend upon trusting, trusting who provided it, trusting the data that went into it, trusting, you know, the, the tuning and the, and all of these things. Um, but we're still in a place where there's not a lot of visibility into that. This is a problem we have in open source.
It's why the massive rise of malicious open source out there, because we don't know who the authors are, even on the popular software. That is good, right there. There're somewhat anonymous people behind the scenes.
And, and I think, you know, AI is gonna force us to rapidly reconcile that because you can't, you, you know, in theory you could take a piece of open source code, you could read it, scan it, do all the things, and get comfortable with the fact that I understand what this is. There's nothing weird in here. But you can't do that with ai.
You're talking, you know, petabytes of data that it's been trained on. How do you know if that's been curated to have a specific bias or not? Right?
How do you know what the model numbers have been tuned to? Can you really prove it right? So it gets to a point where it's impossible to really inspect this.
And then, then you get back to, well, I just have to trust it. I have to trust the people that provided it and, and all these kinds of things. But we don't quite have that visibility mechanism yet.
So I think that's gonna push us in that direction pretty rapidly. Can You talk a little bit about maybe for Sonatype, as AI has Riven risen onto the scene, and I know you're very much overthinking in your approach to this. How has that changed your product strategy or thinking about AI and models and Security?
Yeah, yeah. So early on, our customers started asking us, you know, how do we, how do you help us govern these things, right? So we have a long history of helping organizations detect and govern the open source components that are going into their software.
And so from that perspective, AI is just another, albeit large and hard to quantify component, but it is just another component at the end of the day. And so we're seeing a lot of the same patterns, uh, that we saw early days where we had talked to leaders and they'd say, we don't use open source. And it's like, yes, but, uh, you downloaded a hundred thousand components from US last year.
Um, you know, and so it's sort of a case of leaders say you shouldn't do a thing, and they assume that that's what's happening. And without the tools to validate and govern it, um, they can't know that they're wrong, but they're usually wrong. Mm-hmm.
And this is what we saw with open source. And so we added capabilities to our system to be able to detect, provide metadata around the models, you know, and, and it goes beyond the traditional, you know, security quality and licensing that you see in open source. But now we have to think about bias and, and, you know, other kinds of things, derivative models.
And is the, is the, the data, you know, the software license might be one thing, but the data license might be a different thing. And, and these other types of aspects. So we've had to expand the, uh, parameters of metadata that allow them to reason.
But the most important thing is being able to discover the ai, right? And so we see a lot of people talking about AI usage, and there's sort of two different pieces to that. There's what the tools are, so think co-pilot and other things that are helping you create code on the side.
But then what we're seeing and what we're helping them manage is the developers are baking these models into the product, right? Just like another open source component. And, and many leaders are focused on the first one and completely missing the second one.
Mm-hmm. And so that's where we've been focused, um, you know, because our platform and everything else is already kind of designed to be able to manage that problem. Mm-hmm.
Excellent. Um, you know, someone said to me yesterday, the pivotal point in their career was when they sort of stopped pitching FUD to the CEO and had to start pitching. And here's, here's the value to the business.
Why, why is this important, not just important, but the benefits security brings to the business. If you're gonna help one of your colleagues or customers or friends with their pitch around software security, maybe including AI as well, what are some things you'd want to make sure key points you'd want to make, help them make On their pitch about Pitch to fund, uh, software security projects? Wow.
I know. How much time do I have? I, I saved the easy ones for you now.
I do. I save the challenging ones. 'cause you're The guy to ask.
Yeah. You know, I, I would think, um, you know, pitching them to make sure that they have the investment to be able to truly understand what's inside their software from all of the different dimensions. Ai, like I explained is, is like a whole new, uh, you know, uh, factor that with so many new dimensions.
So what, what we see is so many organizations are struggling to deal with just being able to produce something simple like an SBO m for their existing open source. If you can't do that, you're not prepared for all of the malicious components. You're not prepared for the AI components.
So I think you need to be thinking about, about it holistically and not assuming that things are okay. Um, because oftentimes we're finding that they're not. Um, and it's a, it's a case of just because you haven't found it doesn't mean it's not there.
You know, if I'm from New England, we have radon in our basements, but if you don't have a detector for it, you wouldn't know it's colorless, odorless, tasteless. You have no idea. Just because you you haven't tested for it doesn't mean it's not there.
And that's kind of what we're seeing with, with certainly these AI models that are being baked into software. The developers know they're the ones that are doing it. It's the leadership who's responsible for knowing They're somewhat unaware of these things.
And, and that is not a good, good situation. Yeah. Ultimately, who's gonna get held accountable.
Exactly. Right, right. Yeah.
They're the ones that responsible to know. That's right. Yeah.
So la last topic. Run outta time. We could go hours, you know.
Um, what's, what's top of mind? What are things you focus on focusing on for the next six months or so? What kind of, what are you looking at?
What are you researching, thinking about working on? I mean, of course every, every conversation is like this one around AI in the intersections of it. You know, there's still a lot going on, um, in Europe around, you know, providing the details behind the Cyber Resiliency Act and the product liability directives.
You know, the the community, um, is working pretty rapidly to try to define what those best practices are. You know, because the regulations say if you don't follow the best practices, you'll get fined, but it didn't find what those are. We're in that process right now.
Mm-hmm. Um, you know, and, and a lot of that has to be, has to be done in the next six months. Right.
So there's a lot of work going on, um, to, to, to focus on that. Um, you know, we're seeing other, other countries following suit. You know, India recently released some of their regulations, similar things.
So we're seeing a lot going on there. And that's, that's keeping a lot of us in the, in the industry busy to help kind of make sure that the best practices are, uh, the right ones. Mm-hmm.
So that the, the legislation is effective. Well, good. Well, maybe even if the US is pulling back or redirecting what it's doing, international community is not stopping either.
No, they're not. And every, every, every significant company is a globe in, in software is a global company. So these regulations that apply in Europe are gonna drive action regardless of where people are headquartered.
Right. So I think that's at least some of the good news that we're going to see, you know, uh, we're gonna see that change no matter what. Good.
Well, thank you. Hey, keep up the good fight, man. Thank you.
Alright. Good to be talking here with Brian Fox. Thanks for tuning in.
We have some more live interviews coming up here on Textron tv. Coming to you from RSAC and Broadcast Alley. We'll see you in a minute.
Hello and welcome to the AI Leadership Insights series. I'm Amanda Ani, and with me today I have Albert Roux. He is the EVP of Product at Micro Blink.
How are you doing today? I'm doing great. Nice to see you, Amanda.
Nice to speak with you. So, uh, share a little bit about Micro Blink. What services are, do they provide?
So, Micro Blink is an AI powered, uh, company specializing in, uh, digital identity. So we provide solutions to capture, uh, identity document, classify them and verifies them, uh, remotely. And we have also an identity platform that enables us to verify not only documents, but also biometrics and conduct database checks for our customers.
Alright. So our topic of the day is how artificial intelligence is impacting the cruise industry. So, can you share, um, from your experiences, what are some key use cases for AI to improve the cruise industry?
Uh, definitely. Uh, actually micro blink is, uh, uh, a company was a, a wide range of customers across different verticals, but particularly we're well established in the hospitality and travel. Uh, so therefore we have a lot of customers, uh, who are actually a cruise line.
So I think when we, we think about those type of customers, their main pain points is primarily the user experience. So, onboarding a cruise ship, as you know, is always a little bit painful because you're dealing with thousands of people. Uh, the cruise, uh, lines up to actually, uh, verify your identity just like airlines do.
But also there's additional, uh, regulations that applies to them because they also operates, uh, online chasms. So, but primarily I think for them is to ensure their guests have a optimal experience, especially during the onboarding time. So what does that mean?
That means that they need to be able to verify, uh, their guests, um, identities, uh, in the most, or at least the least intrusive manner. Uh, especially when they ask to provide, uh, your passport, your, uh, driver license or also identity documents and verify, uh, who you are, uh, including your biometrics or your face match. And then pair it also to their, um, sometimes some of those companies that, uh, bracelets that enables you to access, uh, certain, uh, services or even, uh, private islands that MI operates, uh, into.
So I think, uh, the main use case primarily is around onboarding, but also, uh, accessibility to certain services. And third, obviously is, uh, compliance with regulations. So K-Y-C-A-M-L because has know a lot of people don't know this, they are actually a financial institution, so they are subject to the same regulation aspects.
Hmm. Um, do you have any, uh, examples you can share where a cruise line or any kind of, um, company within the hospitality travel industry implemented AI and saw some immediate results? Can you share kind of that return on investment that they experienced?
Yeah, so absolutely. Uh, I think there, there's different ways you can actually verify, uh, someone's identity. So you can do it, of course, so you see when you arrive, uh, at the port and verify the identity via ki right?
So that's one way to do it. And even those skills actually are powered by AI already because you capture information using, uh, uh, a computer vision and OCR or optical, uh, uh, character recognition. Uh, and we, we, I mean, essentially your skills capture an image of your identity document and have to extract that information to verify it.
Uh, they also, uh, leverage biometrics now. So facial biometrics, those are, uh, purely, uh, ai, uh, machine learning models. So in, in reality is they've been doing this for quite some time.
And, uh, what they, they're trying to do, of course, is to optimize the time now that you, it takes to onboard, uh, uh, a customer. So they do it at different levels and at different touch points, uh, during the journey of their passengers. So onboarding so obvious is one, but also, uh, during the course even of the cruise, right?
So let's say for example, you want to, um, disembark and visit the private islands, especially in the Caribbeans, uh, or anywhere else in the world, uh, they're going to, uh, have the need to verify, uh, not only your identity, but sometimes also your age because you have also adults, uh, areas of the ship, but also of the island. So in reality, uh, AI is used at different, uh, stage, uh, from, uh, verification of identity, verification of your biometrics, and also even checking whether or not you're present on certain lists, right? For example, uh, politically, uh, exposed person.
So even though he seems like a simple data match, but he's a little bit more complicated than this, uh, on the backend. So I, I, I think there's a different ways, uh, this is done. Uh, another way obviously is even prior, uh, prior to having you onboarding, uh, boarding the ship is they, they want to optimize their, uh, app experience.
So obviously everybody has a mobile phone these days. So even before boarding the ship, if they can, uh, actually already accelerate your onboarding experience, they will do it. So via, uh, the application, most, uh, major cruise ships now have, have an app that you can leverage to, uh, establish your identity, but also, uh, uh, purchase things, right?
And, and the moment you purchase funds, there's the risk, uh, in near to be, uh, comprised or verifying your credit card, verifying your, your transactions, uh, issuing, uh, maybe a digital key to open the door of your, of your room. Those all, uh, leverage, uh, essentially ai. Wonderful.
So, uh, from your experience, where do companies experience challenge or roadblocks when they're implementing this new AI technology? I think the biggest challenge is, uh, what we, uh, people don't realize is we have to do that globally. What does that mean?
That means that you need to be very able to verify, uh, a wide diversity of documents. Uh, you need to do it for passenger from all around the world. So if you live in Florida, so I'm, I'm pretty familiar with the, the cruise industry, and it's not only Americans or Canadian boarding, those cruise ship, it's Italy, Europeans, uh, people from South America, Africa, Asia.
So the number one challenge is you have a solution that, number one, is easy to integrate with their current systems, especially, uh, billing, for example, but also, um, able to handle, uh, any type of document, uh, globally. And sometimes we have some customer who operate it in zones where there is no internet access, meaning you don't have access to cloud services. But what happens now, uh, if you don't have access to, uh, a server that you can access to verify someone's identity.
So, uh, that experience needs to be actually, uh, happening on device now. So that's where my ProLink actually forte is, is we provide, uh, models, especially machine learning models or computer vision models that can operate, uh, entirely offline and, uh, on even a, uh, something as small as a mobile device. So I think that's another challenge that people don't understand, is when you travel, you don't have internet everywhere on the ocean.
So how do you, uh, uh, provide those services continuously during the, the journey of a, of, of a cruise? So those are, are really the major challenge that they face. AI is advancing quite rapidly.
So what do you see in the future of the travel industry and the cruise industry as it relates to ai? What are some other use cases that you envision? I think the main thing is, uh, to understand AI is a great thing, but also bring some, uh, other risk.
Uh, AI obviously, uh, can help you generic, fake documents or even, uh, potentially, uh, fake, uh, uh, carry parts, right? So the minute you start to have a presence online or, uh, the ability to verify someone ability, uh, uh, identity online, you also, uh, open the door for frauds. So, uh, who said that the person that you just onboarded on that cruise ship is actually that real person.
So you, you're going to have to leverage, uh, a combination of, uh, computer vision model for document verification, but also for the biometrics. So, uh, that is the part that, uh, cruise ship, I think, needs to, to worry about, because now those tools that processors use are much more advanced than before. That's one.
And then you see, you, you have going to have to deal with potential issues just like illegal immigration or, or, uh, uh, money laundering, all those issues. And, and, um, push could be the perfect, uh, opportunities to, for those people, uh, for the frauds to do that. On the other hand, uh, at the same time, uh, I think a huge benefit of ai, especially with the new, uh, what we call the, um, LLMs, but essentially what the chat GPT of the world to not to name them, uh, enable, uh, also, um, those companies to have a better understanding of their customers.
So, uh, having maybe reducing the cost or something just simple as reducing the cost of personal owned ships, uh, that can give information to passengers. So, for example, I mentioned earlier where muscles of scholarship have an application, uh, a mobile application that you can have on the phone. But, uh, imagine now that you can have an intelligent, uh, chat bot who can actually start to ask you questions.
So to get to know you better, provide better experience, tailored maybe an evening for you and your spouse to have dinner, uh, on a cruise and already pre-ordered maybe the meals that you like. So you can imagine the possibilities of an AI who knows everything about you, and then can tailor her a better travel experience for you. So I think this will be, uh, could be something that I'm sure the cruise, uh, cruise ship can, can look at.
I wonder if eventually we'll see AI robots, um, as service providers on cruise ships. Yeah, I think you, you can see that in some hotels already. I mean, they are not actually, uh, actual Android robots yet, but there is some in certain cas around the world or even hotels, you can actually order food.
And then you have that little robot we can bring uses. So I think this is going to be an evolution, a natural evolution of where we see, uh, AI going, probably in terms of customer service experience. I think that's going to be, that's gonna be a great one for passengers.
And you can probably see what, uh, companies like Tesla are doing, where they start to work on their own, uh, Androids. So apix, one of the primary application for this is obviously the hospitality vertical. And, uh, I think that's going to be, um, that's gonna be great for, for customers.
Well, if there was one key takeaway you could leave our audience with today, what would that be? I think, uh, in general, I think for ai, uh, is going to be a huge benefit in terms of, uh, experience for the end user. Uh, when you're boarding a ship now, you, you won't have to suffer through long lines, potentially.
You, you could have done all those things at home, and then all you have to do is to actually go to the ship and, uh, everything else will be taken care of you by an intelligent AI who knows, you know, your tastes and enhance your, your experience of all, and then also diminish the risk to you, right? You don't want to have Craig Mo with you on, on those cruise ships. So I think, uh, if I can leave, um, uh, audience here with, uh, some, some words is I think is going to be pretty exciting for everyone in, uh, in the cruise ship, uh, industry.
Wonderful. Well, I love cruising, so I can't wait to see what's next. Uh, we like to go every year, so all well, thank you so much for coming on the show and sharing your insights with us today.
Thank you, Amanda. Appreciate the time And thank you to our audience. Stay tuned.
There's more. Hey everyone, it's Alan Shimel. We're back here live at the, uh, RSA conference covering Wednesday.
We are live. You can see behind me the activities picked up a little. I think some of the sessions are led out and there's a lot of people heading over to the West Keynote stage.
Magic Johnson is going to be on keying and about 45 minutes. And, um, there's already lines forming and people streaming in. What does it say that Magic Johnson, he's not really known as a cybersecurity expert, draws a much bigger crowd than any of the cybersecurity people we have in keynotes.
But You, you could take a break from a lot of cyber and AI talk tracks, right? Yeah. And go see Naja.
Well, yesterday had Ron Howard, you know, uh, as well. So all interesting. Anyway, I want to introduce you to deepen Desai.
Deepen is the, uh, chief Security Officer at Zscaler, one of the great security companies out there. It's a great story. I was talking to Deep End, of course.
The founder of Zscaler is Jay Chowdry. He's kind of a legendary guy in the cyber. When Jay got involved, we didn't call it cyber, he was the InfoSec space.
He's had success with. I think Zscaler might be his third big company, right? He had two other really big companies, but deepen, you've been with Zscaler, what'd you say?
11 years? 11 years, yeah. So you've been, you've, you've, you've seen this, I've seen the growth.
Yes. Absolutely. It's been an amazing thing.
Deepen. Zscaler is not a company that's, uh, not familiar, that's a double negative. Zscaler is a company that's very familiar to our audience, but maybe there are some people who don't know, right?
So why don't we just get that outta the way, let 'em know who Zscaler is, what you guys do. Sure. So Zscaler is one of the largest cloud security company.
Uh, our motto is to provide Zscaler zero trust exchange. We're like a switchboard that connects entity A tot entity B in a secure fashion. And when it comes to anything that goes out to the internet, our goal is to make sure nothing bad comes in, nothing good leaks out.
And for connectivity to your internal application, we wanna make sure that we're doing it in a way that we're not, uh, we're, we're basically reducing the lateral propagation attacks. Absolutely. Look, I've always explained it to people that Zscaler was the first Network security tool built for the cloud natively.
So I don't mean cloud native and Kubernetes per se. I mean, natively built and for a cloud environment where before Zscaler, we had that Moten castle sort of model, right? You had a big box that so stood in front of your, your land Yeah.
And everything ran through that box, and we inspected it and we snorted it, and we, you know, firewall did and everything else. With Zscaler, we realized there wasn't that Moten castle anymore. We couldn't put that big box in front of everything, but we could look at the traffic as it came over the cloud network to the land or land and inspect that traffic, whether it be in a sandbox or, or some other way before letting it go through.
And of course, the trick was to do it with almost no latency, right? Yeah. And that to me was the magic Yeah.
Of Zscaler. The way to think of it is, as, as users started becoming hybrid, whether it's, uh, working from home, traveling or in office, applications started moving out from that castle that you were describing. They're now in public cloud.
They could be in data center, or they could be in the corporate environment as well. Uh, with the newer technologies, like whether it's iot, ot, ai, now you need security that follows the users and the application. You cannot have that castle and mortar approach anymore where you're back hauling stuff and trying to do everything at just Makes no sense.
It's wasteful, it's doesn't bad User experience. Yeah. Yeah.
And you're not even able to apply security. Agreed. Agreed.
So, but you know, I'm giving you Zscaler 2010 or something like that, not Zscaler today. Your job's to give a Zscaler today. Yes.
So today, again, our, our primary mission is to make sure we enable organizations to adopt zero trust everywhere strategy. And it is even more important now as we're starting to see AI driven threat landscape evolve, right? Um, uh, when you think about human adversaries, they use a certain set of playbooks.
When you think about an AI adversaries, there's gonna be a lot of those unknown, unknown things that we will have to counter against, which is where if you have zero trust architecture implemented, you're essentially simplifying your network, shutting down the vectors or the attack paths that whether it's human adversary or AI driven attacks, you, you're basically able to protect against that. Right? Absolutely.
Um, you mentioned the AI word, checking my watch, we made it about three minutes. Mm-hmm. And so we mentioned ai, of course, AI is everywhere at this show.
Not only at this show, though, it's everywhere. Yep. How is AI changing the game for Zscaler?
Yes. So, so look, as an, as an organization, we are ourself. So I'm the ciso, uh, of the company, which means just like all the other CXOs out there, I do have a job of making sure we're securely enabling AI adoption in our organization.
But being the cyber vendor as well, we are also implementing a lot of those learnings. And we've already done that, where the zero trust exchange allows organization to securely adopt ai. So we're able to inspect traffic going to these AI applications like Chad, GPD Copilots.
We're able to make sure that none of the sensitive data leaks out, uh, because we do TLS inspection over there as well. And then we are able to provide you a full visibility, uh, shadow AI is a reality. Sure.
You know, I was talking to a CSO yesterday, like, every company has AI adoption going on. It's just whether you know about it or you don't know about it, that there is, uh, usage of ai, your employees are trying it out. So that's where Zscaler does help provide that visibility security controls to make sure there is no risk, um, of data exploitation.
Now you ask how is Zscaler using it as well? So we are absolutely integrating AI across that exchange because we strongly believe you need AI to fight ai, right? So this is where across the stages of the attack we have models implemented.
We're also using generative AI capability to do neat things like predicting breach like scenarios because it's able to process large volume of data at scale. Love it. Um, you guys recently came out with a, a, a, uh, report share.
Yes. So just last week we published our annual phishing report. This is, uh, a report that comes out of our security research team threat labs.
Uh, the team, uh, looked at 2024 findings, and this is where we were able to, uh, glean insights into type of attacks that are happening. Um, one of the interesting finding, and we are not surprised, is the overall volume of phishing attacks went down almost 20% globally. Were absolutely seeing a shift from volumetric attacks to more quality attacks.
And AI is one of the reason because they're leveraging AI to craft very targeted email, bringing in context. So let's say the threat actor is targeting organization name, they will look at what all things are going on for their organization at that time. Is there an appraisal cycle?
Yes. Then I will do an equity grant, spearfishing email. Is there a mergers and acquisition talk going on?
Then I'll use that. So they're able to bring in that current context. They upped the game And they're able to craft email, which is flawless.
Doesn't sound like it was written by English as a second Language. Exactly. I know.
So, so we're starting to see more and more of that. And then in the report, we also call out other vectors like wishing where they're picking up the phone using clone voices. Yes.
Uh, we saw video Based clone voices. Clone vi I was just gonna say cloned video. Yes, exactly.
So we're, we're starting to see an uptake on that as well. And as we head into this year, uh, I wouldn't be surprised if we see more and more of these hybrid attacks where they use one vector to establish confidence on that victim employee, and then use the traditional vector to make them click or install something on the end point. Look, I've been in security a long time, as have you.
Right? Did you ever get discouraged? Yeah.
You, you, you shouldn't. Right? It's, it's, uh, like I said, there is always, uh, going to be cat and mouse game over here.
Yeah. There are certain things that you could do to be more proactive. Um, when we talk about zero trust, it's also a journey.
Every milestone you hit, your posture goes up, but then bad guys are also trying to evolve their tactics. And you need to be aware, you need to have that situational awareness to make sure you're, you're getting in the right shape to defend against it. Agreed.
Agreed. Um, what's been your impressions of the show this year? I, I Feel like you're a vibe.
Uh, definitely more crowd than last year. Uh, yeah. How to say that?
Um, uh, unfortunately I spent a lot of time outside the show floor, meaning meeting all the large customers. Uh, but the lot of ai, uh, agentic ai, um, solutions around securing AI or leveraging AI to be more productive. Um, look, we are in that stage where there's plethora of solutions in this space.
Probably over next one to two years, we're gonna see about 80% of these fizzle out. Yeah. And then there will be 20% that will actually result in some good, you know, Pragmatic.
But that's market at play. Exactly. Right.
That's the market at play. I, um, I don't know. I mean, you know, there was this whole rebranding, it's RSAC conference, the RSAC company, they're trying to build a community and a membership that'll go year round.
I think it's a good thing for the industry. Yeah. Right.
I think it's a good thing. I think, I don't know if you saw the cis a, well, let's see, the Department of Homeland Security mm-hmm. Talk yesterday.
You know, I think at a time when maybe government is pulling back from being the, the center of the Yeah, Yeah. Collaboration exchange. Yeah.
That we need an RSA Yeah. Yeah. To, to provide that role.
Yeah. No, and, and, and it's one of the most attended conferences as well. Well, it's the biggest security.
Exactly. I mean, I mean, the fact of the matter, there's no knocking anything, but it's twice the size of Black hat. Exactly.
Yeah. Maybe more now. 'cause as you said, I think it is bigger this year than even last year, and I think last year was 40,000 people.
Yeah. So, leveraging this event as a form for collaboration, and even making it year, year long around, like you mentioned, I, I think it's a good step. Absolutely.
What can we expect to see from Zscaler soon? Well, uh, don't get, don't say anything you're not supposed to. Yeah.
You, you don't have to worry about that. Yeah. But yes, no, um, look, there is lot of, uh, investments that we're doing on both A, there's zero trust everywhere.
P so zero trust for users, workloads, iot, o, ot, um, uh, even even the public cloud environment. And then because we see such high volume of data, so on any given day, we're securing half a trillion transactions globally, or 9 billion threats and policy violations that are being seen. We're spending a lot of time leveraging that telemetry to build AI powered operations.
So both from security perspective, this is a security operations, uh, applications. And then there is also IT operations applications that we're building. Uh, there was a recent acquisition that we made last year, uh, in the data fabric space.
Yes. So that is now fully integrated. We're building apps on top of it.
And the goal over there is the inline exchange is protecting our customers from threats inline, but then those learnings also flow in over here. And we are able to do correlation, bringing additional context, including non Zscaler data set, and then influence policies controls back into that inline exchange. So that's, that's something that we're pretty excited about.
That is, and you know, what's interesting is that it's no longer just attack detection or response even. It's, it is the whole picture. Zscaler, you know, I look back and I, as I said, I've seen Zscaler grow from its start the, the breadth of the platform.
Yeah. Speaks to the maturity Yeah. Of, of the technology.
Anyway, it's a wrap. Yep. Thank You.
Enjoy the rest of our essay. Say hello to Jay for me. Thank you.
Yep. Zscaler here at RSA conference. We're gonna be back in a moment.
Stay tuned. You're watching Techstrong tv. Welcome back to Techstrong tv.
Lisa Martin here coming to you live from Oconee West at RSAC 2025 in San Francisco. This is Techstrong's, 10th year of covering RSAC. We've been having some amazing conversations today with cybersecurity experts, which, you know, 'cause you've been watching since we started.
I've got two great guests here next here to talk about what they're doing in the federal space. Bridget Gleason joins us, the CO at Space Lift, and Irene Deko, the CEO at NOx Systems. Ladies, it's great to have you on the program.
Thank you for joining me. Great. Thank you.
To be Here. Love talking partnership stories. So let's, let's do it about for each one.
Okay. Space lift. Give the audience an overview.
We're talking about infrastructure as code, but what's your secret sauce? Policy driven, governance, security, enabling teams to go fast. It's all about velocity, but you can't sacrifice on security and governance.
So that's really, that's really the secret sauce. And you are enabling developers to go faster. You're enabling platform teams to have more control.
Right. The whole, the whole ecosystem to go faster, because the name of the game is getting your software out there. Yes.
And you can't do that if you're not able to deliver it on reliable, secure infrastructure. Absolutely. So, and that's all that we're talking about today.
Yeah. Is, is around security, and it's becoming more and more challenging and more and more important. Absolutely.
We're seeing, It's kind of a double-edged sword because it's essential, yet there's so much more software being developed every day. Right. And that threat landscape just gets more and more amorphous and sticky and Right.
There's no surprise that we've seen a huge uptick in demand at Space Lift. I wanna give us a background on NOx Systems. Where you, where you based, what do you do?
How do you partner with Space Lift? Thank you. Well, NOx is a very simple concept.
We are FedRAMP as a service. Okay. We host our customer applications in our federally compliant cloud, and we get them FedRAMPed in 90 days for 90% off of what it takes to do it alone.
Oh my gosh. That's huge. So we are so excited to partner with Space Lift, uh, to be able to bring them into FedRAMP, but even more importantly, to be able to use them for us.
We manage, uh, over 20 applications, including Adobe's Federal Cloud, and we need tooling to do that in a compliant way. Yeah. And that's exactly why we're so excited to be using Space Lift.
And how new, how long has the partnership been going on? It's being announced tomorrow. Oh, congratulations.
So you are Like, this is hot. We're breaking news. You're breaking news, ladies.
Thank you. I'm Excited. Breaking news.
Hot off the press. And you know, when our, when our CEO came to me and was telling me about Knox, and like you said, 90% discount, 90 days, I thought, there's no way. Yeah.
And for us, we have this growing demand. Our growth is being fueled right now by large enterprise government organizations, lots of regulatory industries. And so having this FedRAMP piece is so significant for us.
And also being able to deliver that to Knox is really exciting. Is this opening the door for space lift in the federal space? Yes.
To some, some don't require fedra. Okay. And we're able to satisfy that.
But many, many, many do require fedra. The other that Irene and I were talking about is, we were walking over here is large enterprise also, when you have that FedRAMP certification, they know that you've got a, a very strict security checklist that you've already complied with. Yeah.
And so I think that's gonna accelerate also Sure. Time to market for some other companies that we're working with. Well, You're giving them the confidence are Thrilled.
Yeah. You, you're giving them the confidence, the customer base, A hundred percent of What you're able to deliver. Why would some federal agencies not be required to do be FedRAMP certified?
Is that, You probably know that is Yeah. So I assumed it was a blanket requirement across, so The, the, the situations are really, if you're delivering on-prem and space Lift is able to deliver both the SaaS and an on-prem. So if you do on-prem, that's fantastic.
And you're able to, to deliver to the government. Yep. Because effectively you're air gapped.
But for the many, many, many SaaS solutions out there, uh, and to be able to, to operate at the speed of SaaS and at the scale of SaaS, uh, that is where FedRAMP comes in. And that's really where we're enabling space lift to, to really accelerate. Okay.
Got it. Talk a little bit about what federal agencies will be able to achieve with this partnership. What's in it for them?
Absolutely. So, uh, I'll, I'll start off right off the bat. We have 15 federal agencies that serve as our authorization to operate providers.
That means they are our sponsors. And they are thrilled about this because what it means to them is they know that the applications that sit in our boundary, the applications that they consume, are that much more secure, that much more, uh, observed and, uh, compliant with all of, not just the FedRAMP regulations, which are very important and really the name of the game. But also there's many additional regulations around now AI coming out Right.
Around cryptography coming out. Yeah. Because of course, software is moving so quickly.
Yeah. And so what, as we harden our stack with tools like Space Lift, um, it means to them that they feel a lot more confident. Right.
Consuming from our cloud. And, you know, I do a lot of marketing. I've, I've been in marketing for a long time, and confidence is critical.
It's not a marketing term that is to, to be able to give a developer a platform team a, an agency. The, the trust and the confidence that their applications are secure is not table stake. It's table stakes.
No. It, it, it, it absolutely has to be. And Irene and I were talking earlier today about how this, this administration is looking to modernize a lot of the infrastructure.
Yes. It's, That's gonna require for them to do it a lot more software companies that are certified to, to service the, the government. And it's part of the reason I'm sure you're seeing a big demand.
We're seeing a big demand because for us to fulfill that, we've gotta satisfy these requirements. So as you said, it's trust. Yeah.
But it's Also, there has to be the security, very real security. And it is frightening to think about with AI and some other tools out there that the threats are getting bigger. And so being able to have a platform like Space Lift that is very strong around security, compliance, governance, et cetera, is critical.
One of the things we heard today, we were at the same, um, talk this morning, was companies that want to allow their security folks who are working on compliance issues, everything you do need to do to satisfy compliance. Yeah. They would like them to actually be working on security issues.
So a platform like Space Lift that can take away some of that, those compliance chores and busy work Okay. Will enable some of the security people. What did they say today?
How many? 500,000 open positions open positions in, in cybersecurity security. Yes.
Right. Yes. So we've gotta make sure that the people that need to be, that can be doing security are working on it, and space lift can help take away some of the other compliance and auditing and some of those other requirements that we can help fulfill through automation.
Right. And so you have the security folks focused on what they Need to focus, and that's what they focus to do. Developers wanna develop security professionals, wanna secure by being able to offload and automate some of those, I don't wanna say menial tasks, but tasks that take time and resources is huge.
We, I don't know if you know that we released an AI agent about two weeks ago, uh, Saturn head ai, and I mean, you're talking about the mundane, repetitive tasks for DevOps engineers. That's finding out what happened when a deployment fails. Yeah.
And it requires looking through very complex voluminous logs. It's mundane, it's repetitive, and it often requires a more senior engineer Okay. To be parsing through those logs.
So our agent can go analyze the logs in plain English, give you a description of what happened. I really like that. Like That.
And then also, these are the things required to remedy it. So again, making sure that we've got the more senior people deployed on the really the highest, highest tasks. Yes.
Yes. So from a sales perspective, are you selling into developers? Are you selling into security teams?
Is It both? Yes. Yes.
All the above. Yes. Okay.
We get interest from the developers. We get interest from security, we get interest from CIOs, we get interest from platform teams. Okay.
It kind of comes across the board depending on what their lens is to look at it. Okay. What excites you?
I mean, there's so much. You talked about ai and we can't go to a conference without talking about ai. Right.
You can't even a fashion conference's gonna be talking about AI and fashion, I'm sure, but it's been around for so long yet, the chat, GPT Catalyst a couple years ago just brought it front and center and everybody is diving in head first, but it also opens up vulnerabilities por and more opportunities for the bad actors. What excites you about some of the positives that you are seeing in the security space where AI is concerned versus all the, the fear that's out there? Yeah.
Well, I can tell you from just operating our federal boundary, um, it is a game changer to have AI reasoning agents that we can custom train on our data run with open source models, that we are able to fully understand and actually take those agents and scan our boundary for issues with the boundary not being compliant with FedRAMP. So rather than having to do something manually only once a year or once a month, or as often as you can get to it, we're able to truly do continuous monitoring. And that is only enabled by AI reasoning agents.
Um, which is why we're so excited because, uh, yes, the bad guys are gonna move fast. Yeah. But we're able to move faster.
That's so important because it's, it's like the AI arms race. Yeah. We see it country to country, all the competition going on.
And we see every organization, um, embracing, really embracing ai. It's rare if I talk to A CMO who's not embracing it, at least generative ai, and now it's a Gentech AI as well, and ephemeral ai. Talk a little bit about the go-to market strategy sales, CEO.
What is that gonna look like from both of your lenses With regards to the partnership? Yes. Again, we were talking about this on the way over.
I asked Irina, so when will we be FedRAMP authorized? Yeah, exactly. And she said, June one.
June One. That's a roundup. Hit go.
So again, I've got, I've got a pipeline of opportunities right now of, again, large enterprise regulated industries, government organizations that have already reached out to us and are looking at space lift. So I think we'll continue business as usual. We just, now there's a gap that we, we hadn't filled and we thought it was gonna be, honestly, Lisa more than a year and very expensive Yeah.
For us to do it. So this is like Christmas For me to Have this. I mean, it's so, it's so thrilling.
And I think for our customers as well, because they're trying to do the same thing. They're trying to create resilient Yes. Scalable, secure infrastructure for their environment.
So to be able to satisfy that just feels really great. I think it's, it's definitely a win-win. It Sounds like there's all already a lot of momentum from a demand perspective.
Are you seeing the same thing on the NOx side? Absolutely. So part of this partnership is actually, we at Knox are installing one space lift worker per application inside of our boundaries.
So that's already, uh, almost 20, uh, workers installed. And as additional customers come onto Knox, they're using space lift. But the other thing I'll tell you is that even for example, one of our customers, as I mentioned, is Adobe, they're now starting to look at space lift as something they might wanna be using, even beyond just their federal application, but in their development team, uh, beyond.
So it's a, it's a really, uh, because it's such a broadly applicable tool, not just for federal security, but much more beyond that. It's a, it's a great place to, uh, to really, uh, spread the word. Sounds like you guys are gonna be awfully busy.
Yes. That's a good thing. Right?
Absolutely. I just wanna shout it from the mountaintops I'm so enthusiastic about. I love it.
I'm so enthusiastic about the partnership. Again, it fills a great gap. Yeah.
I think we're gonna be great partners. It's so mutually beneficial and, uh, reinforcing Yes. Of one another.
So we're both, we're really excited about it. And, And you're gonna be able, you know, we talk about cyber resilience all day long. It's a journey.
It's not a destination, but it's also one, like, I always wonder how can organizations truly become resilient? How is this a facilitator of that? Because resilience is the goal for so many organizations across industries.
Well, this is one, this is one step towards that. Absolutely. You know, one, one thing to, to really, um, I think the, the position we take at Knox is to be, uh, aggressively conservative, right?
Okay. And you can only be aggressively conservative in your security practices, in your, uh, resource configurations is if you're able to one, automate, but be, observe exactly what you're doing. That's why we use infrastructure as code.
And we always have, that's why we wanted to use space Lift right out of the gate. And, uh, and we, we said, please, would you get FedRAMP please so that we can, we can use you. Um, but that is the only way to stay resilient if you're able to automate and be kind of everywhere, all at once, all the time.
Yes. That's the only way. Right.
What do you hope for? Last question for both of you. What do you hope here we are almost in May, June one hit the ground running.
What is kind of your dream for the rest of 2025 as partners? Well, I can tell you, uh, we are gonna be bringing on a number of, uh, uh, applications into the NOx boundary. Every single one of them is going to be running, uh, space lift workers, uh, to orchestrate their, their environment.
Um, and what I'm so excited about is, uh, to really be able to, to see this, you know, mass machine humming. Yeah. And, uh, and you know, there's, there's no doubt that there are going to be, you know, there, it wasn't that long ago that Log four J took our entire industry down for, you know, months.
Yes. And, um, there will be more. And what I'm very excited about is that we are, we are building, constructing this boundary, um, in a very hardened way, in a very, uh, uh, thoughtful way.
And space lift is a key part of that. That's critical. Ladies, thank you so much for joining me on Techstrong tv.
Thank you. It's been great to have you. Likewise.
Learning about the partnership. Congratulations. The news comes out tomorrow.
We got to break some news. I always love it when I get the chance to do that. But it sounds like you're creating that resilience that organizations, not just the federal agencies, but in every industry That's right.
Have to have That's right. This definitely goes beyond just federal agencies. Well, so it's really thrilling.
Well, congratulations again, and we'll be watching your trajectory. And we thank you for sharing your insights on Text on tv. Thank You.
For my guests, I'm Lisa Martin. You are watching Text on TV Live from RSAC. This is day one of Wall to Wall coverage, four days here on Textron.
Stay tuned. My next guest joins me in just a minute. Hi everyone, welcome to the Platform Engineering Show.
I'm your co-host Alan Shimel from Techstrong. And let me introduce you to my co-host here on the show. org community.
Um, first of all, hey Luca, welcome. It looks like from the blurred background, you, you're home in Milan still? You home back in the van?
I'm in Madrid. Back in Madrid. Okay.
Yeah, man, you are the Globetrotter dude. Good for you. Um, so what is happen, last time we checked in on you, you were in Milan.
Did you go right from Milan to Madrid or what, what's been going on World? Yeah. London this morning.
London this morning World. Oh, you just got taking the van. Yeah.
Yeah. And I'm taking the van back to Milan, so that's why I'm here mostly. Um, I'm, I was gonna go to Barcelona.
We have some workshops that we're doing. So apart from engineering workshops that we're doing tomorrow, no, on Friday in, in Barcelona. And I was just gonna fly there and back to Milan.
Um, but then I was like, well, actually, you know, anyway, logistics, but we wanted to bring the, the van over to Italy. So I was like, okay, let me just land a day earlier, drive to Barcelona, and then drive from Barcelona after a work trip to Milan, which is gonna be a long ride, but hey, it's friends in between, so it's gonna be nice places to stop by. Good for you, man.
That sounds like a nice road trip. Good stuff. Yeah, Luca, so for this episode of platform, the platform engineering show, we're talking about steps to platform engineering.
org, right? Correct. And the article is actually the show notes.
Yeah. Yeah. We'll, we'll put the notes in The article is actually nine steps.
I don't know if we'll go through all nine steps, but we're, we're gonna have steps, steps to platform engineering. Hell. But, you know, it's kind of a funny premise, right?
'cause we're here trying to say platform engineering is a good thing. It's a way out, it's a way to a, to scale a heaven. Yeah.
Right? Where, where does it all go wrong here? That it, it could become a hell.
Yeah. So yeah, this, this, again, this stems out of this like nine steps of, uh, puffer Engineering had article, which actually stems from another article, which was the, I don't know how many steps to DevOps held that I had written prior to that. And then it was interesting just to see, because to your point, right, like everybody was like, oh, you know, pop great, but I just moved to de from Dallas platform engineering, all my problems are solved.
Um, and then, you know, obviously you start seeing this like anti-patterns emerge within the platform engineering practice too, where well actually, if you don't do it right, you end up, you know, potentially even in a worse place than, than where you started. And so I think like, if we start from the top, like the first thing that I see a lot of people, a lot of teams, um, making as a mistake is, okay, let me take, you know, the sort of like hodgepodge of DevOps, cloud ops, SE infrastructure teams, and just rebrand them to the platform team. Um, and it's actually interesting, you know, we start, uh, hosting these trainings or, um, organizations to go through from a, you know, to, to kinda like upskill their team.
And one of the things that I see resonates the most with, um, with platform leaders is this, right? They say, you know, every, every time I say this, everybody knows. They're like, oh my God, yes.
So true. It's just like, I, I inherited this legacy of different teams. Now they all sit under me, they're all part of the platform engineering org.
But actually nobody has a clue as to what platform engineering even is, right? And so I think like the, the first mistake down to like, you know, um, sort of like slippery slope of, of the down platform engineering hell, is this idea of like, okay, well let me just like rebrand whatever I have in house right now with no upskilling, no retraining, and just hope for the best, right? And it just doesn't work, right?
Because you have people that fundamentally approach infrastructure the way the, the, the, the relationship between developers and infrastructure as well in a very different way than, um, technically what a platform engineer should do. And so without retraining, without shifting the mindset, it becomes very, very problematic. And that leads right into the, sorry, second step, which is this product mindset, right?
Um, that we've talked about before. We had a full episode on platform as a product, as one of kind of the core principles of platform engineering. And that's really, uh, you know, also what's, what's missing a lot of times because there's no retraining, building a platform just gets treated as this kind of like one and done, um, sort of infrastructure project that's like six months or whatever.
Um, you know, I'm gonna teach developers something new, I'm gonna implement something new, and then I'm gonna move on to the next thing. And of course, that's also recipe for disaster because like we said before, previous episodes, really the point of building a platform is that it's an internal product. Um, and it has internal customers, the application developers or other users as well, security teams, architects, even the, the, the infrastructure teams themselves can be used on the platform.
So the point is, you have to ship it as a, as a product, um, implement product best practices, and really think of it as a product, not just from a technical perspective, but also from a business and go to market perspective, where your internal market is your, you know, internal town. The total adjustable market is essentially the size of your engineer organization. Um, and so that, that mindset shift towards platform as a product is essential, is part of the retraining.
Of course. You know, it can also help obviously having, um, you know, a, a a product person or multiple product people within the platform engineering organization that lead this transformation. It helps if executives understand this and support this change.
Um, but at the end of the day, that is another thing where if it doesn't happen, you know, you're, you're, you're setting yourself up for, um, failure, right? Um, so maybe we can start from there, um, and then we can kinda like dive into, into, into other, uh, steps too. But I think that's really where we see in the community the first kind of roadblock and, and where, you know, the trainings and the courses that we've done resonates so much with the, with the market because, um, you know, everybody understands it.
This idea of like, okay, you know, puff from engineering can solve all these problems, let me go do it. But then if you don't do it right, if you don't upskill your people, it's very easy to, you know, to get stuck very, very quickly. Yeah.
You know, I, I, I think one of the things about that too, Luke, or something you said right, right off the bat, which is for a lot of organizations moving to a platform engineering model, we could call it that, right? Yeah. Is almost like a lot of recycling instead of creating new, right?
Mm. Mm-hmm. And granted that there's nothing a manner with that per se, right?
You, you, you do wanna reuse these assets and you do wanna make it all work, you know, tightly, but you, you can't, you, you can't just put a fresh coat of paint and change the sign above the door and say, voila, you know, life of engineering. Yeah. You know?
Yeah. It, it, it takes more than, than just a fresh coat of paint and a new name on the door. Um, and I, I think, you know, I'm guessing, right?
You guys have the course. I don't, I haven't taken the course, but I would imagine it has to start off with, you know, preparation is, is the key to this, right? Having a plan of, of, of instituting this platform engineering model across the, the organization and working with DevOps and SRE and, and ops and, and security and all right, everybody's gotta get buy-in.
Everybody's gotta understand what it is. Everyone has to understand what they've gotta do differently or what they've gotta upskill on, or, or how this all fits in, like anything else, right? Fools rush in where, where wise men dare to tread, right?
You, you've gotta, you've gotta, it's all in the prep, I would imagine. Yeah, absolutely. And, and, and I think like, um, a few things that you said that I think are, are worth unpacking.
One is this like fresh thing of paint, right? Which is so true. Like this is one another huge, I think, um, you know, challenge that emerges when people are just like, okay, I have a platform engineering bandaid because you know, my execs write on Garner that is cool and they should invest in it.
Um, and so now I need to go do it and I need to show something for it, right? And so the first thing they do is they focus on, you know, the, you know, re re repainting the facade, really, right? So it's like, hey, let's, let's, let's put like some, some ui, some portal, something right on top of the entire setup and call it a day, right?
And it's like we're down platform engineering. And of course, the problem with that is that actually, you know, I, I do think that that visualization is an essential component of platform engineering. Um, but it needs to come with a layer of automation and ization underneath it.
Otherwise, what you end up being is, um, you actually get the, the, the, the sort of like the second step of buy-in by executives because they're like, oh yeah, this, this looks great, right? Um, it, it's, it looks like we've, we've, you know, made a lot of progress and so on, but then actually there's no substance underneath. And, and then you end up quickly in a place where you, um, you're sort of essentially misusing tooling that is meant to be front end tooling, um, to build, you know, to build the entire platform.
And, you know, you can't, you can like shoehorn your sort of like business logic into this, this front end module and so on, and, and, and, you know, you end up creating massive tech debt down the line. And that's one of the, uh, it's already one of the, I would say, another huge kinda like mistake and, and kinda like step to have is this idea of like, okay, start from the front and first, but also, you know, um, and so really not following, uh, architectural best practice, right? Like, yeah, I think it's very important to understand that building a platform is just like building any application.
Again, it's just an internal product. You need to start from the backend and then figure out, okay, what pretty facade, what door do I add to my door, to my, to my house, right? Um, you don't wanna start, as we said before, from like the house and the win from the, from, so like the doors and the windows, and then kind of like add, you know, the walls and the foundation, uh, after, right?
Um, so, um, so, so I think that's, um, that's like a very, very important thing, um, to avoid. And then your point, right? It's about planning.
So, um, this is where I think one of the, um, one of the most significant standards that, that have emerged in the commute in the last couple of years have been this reference architectures or enterprise grade platforms. Why? I mean, I don't know if you're, you know, if you remember like two, three years ago when people started talking a lot about platform engineering, um, you know, like in places like Cube Code and saw, I remember, you know, three, four years ago, I had to explain to virtually everybody I met, okay, what is platform engineering?
You know, what do we mean by this? What do we mean by that? Um, and then, you know, a couple years ago there was this clear inflection point where you could, first of all, everybody was talking about it and everybody was interested, but then also you could finally have a real conversation about it because there was this visualization, which again, it's why I think it's so important to visualize thing.
There was this visualization of what a platform, uh, target architecture can look like, right? And all of a sudden people had a common ground to have that conversation and to think about, you know, backend front end, okay, what do we mean by this? You know, how do this security tools interact with our platform?
How do observability tools interact with our platform and everything else, right? However, I also think it's important to mention that, um, and, and so, you know, like the lack of a plan is certainly another step to hell, right? But then I think there is a subtle step right after that, which is, okay, I have this beautiful target architecture that I want to build against.
Great, let's go build it. And then the mistake that people make is, okay, let me try and do everything all at once, right? Um, and, and build this like amazing platform layer that is super secure that has all observability built in, that is making everyone happy, right?
And that's, that's I think, a, one of the, the, the big problems here is because platform engineering initiatives touch so many different stakeholders, it's very easy to fall into the trap of trying to please everybody. Um, and that is a, a sure recipe for, uh, failure in my opinion, because I think the way we should approach it is you know, we've talked before about this idea of minimum viable platforms, really taking, again, this like product management best practices of starting small and iterate from there. Um, but what starting small means is it both from a technical estate perspective, right?
So selecting one, maximum two representative applications and their respective dependencies, and start from there. But then also start with like one team and especially one set of stakeholders, right? If you're trying to, you know, make the application developers, the infrastructure people, the security people, the architects, the executives, try to make everyone happy at the same time, it's very, very, very hard to keep momentum and traction for your platform initiative.
Whereas I think, I don't know if you spoke, if we've spoken about this before, I know you and I have offline, but you know, we've, we've, um, I think it was actually part of the, um, the predict 20 20 25, um, predictions, right? This, this idea of, um, the, um, the Pareto Pareto, um, pro efficiency, right? Um, which is similar to the 80 20, the Pareto principle.
Um, but there is a subtle difference, which is interesting, I think, which is essentially is, you know, in, in, in layman's terms, like don't p**s anyone off, right? So, um, um, which, which is like, okay, you need to make life better for some people, right? And, you know, in the case of developers, that's, that's side of the conversation.
The DevOp cell is easy, right? Like right now they're waiting for like two weeks to get an a database provision by their ops colleagues. Like to make that 10 better, it's easy.
You're just cut it in two minutes. It's like cell service. Um, uh, so, so that is a 10 x, but then it's important that that doesn't count at the expense of, you know, getting your security folks mad because now you're making things less secure or, you know, um, whoever else, right?
Like infrastructure people now, um, are mad because, you know, you built, you didn't build your platform, right? So it actually, now self service means developers can just like click a button a hundred times and create a hundred different resources that then the, you know, infrastructure people need to deal with. So like, those are the type of of things where it's like, make sure that your platform really makes life easy for somebody, but doesn't, you know, is at, at worst a net neutral for everyone else.
A best in net positive, but it's never a net negative because the moment, even if it's like a 10 x better for some, for, for for few people, for few stakeholder groups, but even just like a minus 10% for somebody else, you can bat that somebody else is gonna, you know, like, uh, uh, like put up a crazy fight to stop this thing. Um, and, and it's a tragedy of the commons, right? That this like large enterprise or transformation run into because, you know, it is better for the organization anyway, but that person doesn't care because that person is now 10%, uh, worse off.
And you bet they're gonna fight, you know, you know, they're gonna give up their life, uh, to block this, this platform initiative. And that's kind of just the reality that we live in, right? You're dealing with humans and, and, and so just to kind of like put a ball on that, I think that's the, that's the last thing I would say is, you know, another huge mistake is just like looking at this as a technical problem to solve, which is very natural for engineers as opposed to this like multi-stakeholder complex cultural problem, which is really human problem that we've talked about many, many times.
And, um, and, you know, and that's the sure way to, to say it in my opinion was we were sitting here laughing. No, no, but I'm sitting here laughing 'cause I, you know, we were talking before the show today about the Google migration going on here, uh, with tax showing f your chairman. And, and that's kinda where I'm at, right?
It's just, it's more than a minus 10% for me. It really kind of Yeah. Sounded like it rips at me.
Yeah. But, um, I don't care how good it is. It's not, it's just not, you know, I'm going to not accept it so quickly and it's gonna, they better gotta make it right.
I, and I, I, but I think that that's a good lesson and, and this, and, and quite frankly, this a DevOps lesson too, is it's not just about the technology. It's not just about the technology. It never is, first and foremost is people culture, right?
Because you can, it's a lot. It's pushing rope uphill to get people to accept technology or process that they don't buy into if they don't buy into it. I, and look, I this is 30 plus years in business, right?
35 years in business. Yeah. I, I've run into this, not just in it, but in general, if, if your team doesn't buy into what you're selling, right, what you want them to do, it is, it's pushing rope uphill.
You don't want, it's shoveling sand against the tide. You're just not gonna win. Yes.
Right? You gotta win 'em over. Yes.
Who is, who's pushing back, um, on, on DevOps, right? Because to your point, it's a similar, like, it was like a cultural change, right? And, you know, I feel like looking back, it feels like everybody was agreeing, but I'm sure like not everybody was agreeing, right?
So up here, everyone was agreeing, sitting around the campfire singing kumbaya, right? Right. But the fact of the matter is, it's the same people, you know, and I'm not dissing anyone, but a lot of engineers and, and folks say, yeah, that that culture stuff is all fine and dandy.
What's the IIC detour? Am I using here? Are we going get ups from Jenkins, Jenkins or you know, Jenkins, Jenkins Jenkins, and what's my plugin and what's that?
And, and that's what it's about. It's about moving, you know, shifting security left. I don't care.
But you know, we, the testers, we don't need no testers. I'm using this new testing product, right? Yeah.
That's automated. And, and so like, they give their mouth moves when they talk about people and culture, but at the end of the day, they don't meet. Yeah.
It was about the tools, all about the tools. Mm-hmm. And yeah, and it can't just be all about the tools.
I mean, I, you know, I'm sorry, but tools are important, don't get me wrong, but I don't even know if they're the most important. Right? Right.
I still think people is is where it's at. But let's, so, so look, let's assume we, we get off to a good start. We do the right things from the start and, and we're up and moving, right?
We're, we're progressing down this platform engineering on the road to heaven, stairway to heaven. What could go wrong that makes the U-turn, you know, after we, like, after the train left the station, right? What else?
Yeah. Where else can we go wrong here? Yeah.
Well, I think it's the same things, you know, um, it's just like a later stage, right? So the, uh, I do think that that getting off the ground is the hardest thing. And what's also interesting is, you know, I think it's important to understand like platform engineering is mostly a enterprise thing, right?
Uh, or at least like mid-size sort of like engineer organization and up, right? Because that's where the problems that platform engineering solves are most badly felt. Um, and so, you know, um, and so it's important to, I think mention like you basically in this situations, in this companies, you never start greenfield.
Like there's always an existing legacy brownfield complex enterprise thing that you need to deal with. Um, and so it's not like you're kind of starting this platform engineering initiative in a vacuum anyway, right? So even if you're starting new, you need to start wherever you are.
And, and, and then if you already are on track, it's actually, you know, because I'm seeing it where I go in and I do these trainings with like large enterprise, and some of them are really at the early stages of their platform journey. Some already have like a platform team of like two, 300 people. And granted, some of them are just rebranded, right?
And they need training. But some of these people are proper platform engineers that have been building platforms for years. Like they know what they're doing.
Um, but they're, the challenges are very similar, which is like, how do I get adoption? How do I get buy-in from different, um, you know, uh, uh, stakeholders, whether it's executives or others. And so you're just at different stages of it, right?
Which is why, like, the way I think of platform engineer initiatives is, you know, you have this like MVP phase. If you're at the very beginning, um, then you have this kinda like production readiness, right? When you want to go from like, okay, you've proven the, the proof concept all the way to, okay, let's go to production with the first set of applications in the first one or two teams.
And then once you're there, you go from production readiness to all, you know, all the way to full scale adoption, right? Just like, okay, we're gonna go to the entire organization. And every step of the way across that journey, you have, you know, basically just like a permutation of the same set of challenges, right?
Which is like, how do I convince people? Um, right? And, and maybe like the first time is like, well, how do I convince the first team?
And the first team is like, you know, you probably wanna start with like a, you know, pioneering team, I would call it in the community that is like, um, you know, the team that is, that are like more comfortable with like, new technologies, new setups, you know, maybe the first one that implemented Kubernetes and containers back in the days, or infrastructures code and terraform and stuff like that, right? The one that you use to, you know, effectively like stress test new paradigms, um, and, you know, but so the set of challenges that you need to solve for them is radically different than the set of challenges that you need to solve for the nth team, which is, you know, the laggards effectively within your market, within your organization. And they, you know, they're just, they're not.
So with the firmer, maybe you need to figure out, okay, what is the right way of, you know, obstructing this underlying complexity while still giving them control? Because obviously they're the people that like control. They're the people that like, you know, their infrastructure, uh, you know, to like being able to get their hands dirty.
They like their arm charts, whatever. And then the, the, the latter, the, the last group that can just be like, well, we don't care. You know, we're very happy to click around, but it's like, it needs to meet us exactly where we're at because we're super lazy.
And I, I don't wanna, you know, you know, jump into another interface or anything else, right? Which anyways is best practice. Like you should always meet developers where that, and the users in general, but, you know, so, um, and, and, and it is the same thing for executives.
It's a very different thing that, you know, at the beginning you're asking for, you know, like half a million, 2 million or whatever, depending on the size of your org, when then you're asking for like, you know, 30 million because you're, you're scaling this up, you're, you know, now you're like, you're no longer 10 platform, 10 people platform team. You're like a hundred people platform team, right? So, and so it's like, how do I, how do I keep realigning my platform engineer initiative to their priorities as their priorities change as well, right?
Because it might be that last year their priority was employee retention this year is, you know, my, you know, I need to cut my bottom line or increase my bottom line, right? Like, whatever, right? So, so it's like it's, and again, and, and it's always just like constant cultural play of like, you know, know as the organization evolves as this like complex organism, how, you know, does the platform evolve with it as it grows within it?
Luca, let's step back for a second though, right? I, I was reading an article the other day and it was like a crazy number. Like 70% of it initiatives are not successful.
They don't necessarily fail and maybe end up in hell, right? But they're not, you know, if this is the bar for success, they don't make the bar, right? Right.
Hell maybe is down here. Is this, is there a similar thing in platform engineering adoption curves where maybe we don't quite get to hell, but maybe we're a purgatory, right? For, for a time where, you know, we didn't get to heaven per se, and we're not in hell, but we're somewhere in between.
Yeah. Yeah. A hundred percent.
I think it, I think that's the na you know, I think that's the na the natural state of, of most, um, of most things in the enterprises, this kind of like stuck in the middle, right? Of like, you know, because it's just so hard. It's, it's, you know, you have, you have, you know, at the beginning it's easy because maybe it's easy, right?
Because you have this like, set of pioneers that are like driving change. They're really passionate about it, right? And then it's like, okay, you know, and you see that's, that's why I think it's very, very important to think about it through the lens of a product.
'cause you see the same thing with any product that goes into any market, right? Where it's like, okay, you know, it, it requires, it's a different thing to get your first million revenue than, you know, the, your first a hundred million of revenue and then your billion of revenue after that. And it's like, how do you evolve across all those things?
And so, and, and it's so easy for, you know, and, and, and, and so how many unicorns do you get? Very few, right? Um, and, and the reality is that most people, you know, end up on some, like tens of millions of revenue.
And that's, that's kind of like where everybody's happy, right? And, and so I think that's also the thing is, is like, you know, do you, you also need to keep dr like have an intrinsic and extrinsic motivation to keep driving this forward where, you know, maybe the had platform who's so passionate about your platform engineer initiative is content now with having onboarded like your first like 10, 20% of estate, 20% of teams, um, you know, out of like 10,000 developers, that's already like a huge success, you know, and, and, um, and kind of like happy days and they moved on to the new better paid role or the next company. And, and, and so like it, and then there's no driving force.
So I think this stuff is normal, happens all the time. Um, and this is also why I think, um, at the end of the day, the, the more successful platform engineer initiatives that I see are, you know, know, are, are prioritized across the, you know, throughout the, the, the sur chain of command all the way, especially to the, to the executives. Um, because you know, when it is, like, it's something that really, yes, you need to consider developer adoption, yes, you need to consider like all the different user preferences.
But at the end of the day, I can tell you there are, and is where I think it also becomes a, not just like a cultural, interesting cultural conversation within the organization, but, but especially like also across like actual culture cultures. Like we traditionally define them, right? So like across different countries and different regions in the world and so on, where, you know, I think we said this before, but there are clearly like platforms, initiatives, and, you know, more top-down cultures are more successful, um, because they're just top-down imposed, and that's it.
You know, that's what we do. And period, like, there's no conversation. It's not discussion.
It's just what we do because we're a regulated bank and, um, and the developer doesn't have much of a say, right? Um, now I'm not saying that that's, that's the ideal state, you know, because every organization is sort of different, although not as different as they think they are. You know, everybody thinks they're like a special snowflake.
Um, but, um, but at the end of the day, um, you know, having that, uh, if you can have that top down thing, that's where I think you can really drive and sort of like, you know, hit escape velocity and, and, and, and kind of like get to the entire company. Otherwise, it's just, you're gonna be relying on how good that particular leader is within the organization, um, and how motivated they stay throughout the, the hassle of it, right? And then it's just like a founder, like, is a founder happy with like a 10 million valuation or a hundred million valuation?
Or are they one that kinda like shoots for the stars, right? So, um, it's, it's a little bit of that. And I think even more complex because, you know, you just add an entire politics layer within these organizations than I, I think you don't have, actually, if you think about like, you know, I mean, you've done a lot of startups.
I'm doing my, my first one, but, but it's like the, the, um, the, you know, you, you actually have a cleaner discovery mechanism with the market, um, because I'm selling something. If they like it, great. If they don't like it, I need to change, right?
Like, um, whereas in, within an organization, it, you know, it, when you're building an internal product, the, the, the feedback is not that direct is not that instant. And you have all this sort of like derailing, CIO says like, actually, we need to do AI now, right? So like, that's actually what happens.
And so like, I think it's, it's even easier to, to, to get lost in all of this and, and just go like, look, we're, we're 30, 40% of the well get, don't get, you don't get clear signal, right? Yeah. When, when you're selling to consumer or even a B2B, you as a start of your small organization, customers tell you, yes, no, maybe I don't like this.
I like that when you are going internally, there's the politics and the, there's just no clear signal. I'll, I'll leave it at that. Yeah.
You know, but it's an important thing that you mention here. And, and I've seen this over and over in enterprises through my career, call it the orphaned project, or the orphaned, you know, movement where, right. You know, charismatic guy, high guy or gal high up the food chain, this is their baby, they're gonna push it through, and then either they lose their mojo, right?
They don't have that kinda juice to put it through, or they leave the company, or, you know, something else happens. And now all of a sudden without that top down push, all the naysayers come out. You know, all the people who said, I always, I never liked that.
I never wanted to do it. They made me do it. I'm not on it.
I'm not on board. You know, you, you get that a lot. And you know, this was an interesting thing.
Oh, you know, you have paralleling the DevOps journey. This was a huge discussion in Dev DevOps is can you do bottom up DevOps? Can the developers and ops people say, Hey, this is, this works for us, right?
Yeah. And, and you know, the long and short of it was, yeah, you can get some bottom up, but you always need air cover. If you just gonna do one little team over here, you know, off on the side, yeah.
You don't need necessarily a, an exec buy-in. But if you are going to do it at an enterprise scale, try to do it organization wide without air cover. You have a good frank Gary Groover, he, he, uh mm-hmm.
He used to do, he used to run software for HP printer division, and then for Macy's, the retail company. Yeah. And he's written a few books on this, right.
On why you need top down air coverage. Yes. You need, you need executive sponsorship for anything like this.
Yeah. I mean, it's just, yeah. And all, and all the way through, right?
It, it's like, um, you know, it's like a lot of people, like when they talk about, you know, if you zoom out politics to the macro, to the macro level, right? Where it's like, oh, you know, China has this like multi five year plans, right? And like, we're stuck, you know?
And, and, and it's a little bit like that where it's like, yes. You know, like I, you know, capitalism is a great discovery mechanism, right? But, um, but then it, it, you know, then you have this like, mutations of it where it's like chronic capitalism, all these things, right?
Where it's like politics gets meddled with politics and then it actually becomes a, a less good discovery mechanism or, you know, progression engine actually than if somebody just says what, what we do. Right? Um, uh, you know, so it's, uh, yeah, I, I, I, I think about this, um, a lot 'cause it's, it's, it's very interesting.
And at the end of the day, you know, organizations are not democracies either. Like, they're not, they're not meant to be, right? There's like somebody that just decides and then they just like, and, and, and, and that's how it works.
This is why, you know, when you have like, nimble teams, it works. There's somebody that just dix a cult. It's what it is.
Peer, you know, and it might be right, they might be wrong, but at least you're moving, right? And then, you know, as you grow, you lose all of that, right? Yeah.
You know what they say, democracy is the most, ineff the best of the worst for of government because it's so inefficient like that. And yeah. And there is times when, you know, a more structured, kinda, this is what we're going to do.
Path does the work, the Navy Yeah. The work is in the Navy. Yeah.
There is not. Anyway. Hey, Luca, we're about outta time, man.
I wanna thank you for joining us today. Thank you. We have the, uh, the URL for this article.
You can go check it out. Uh, we'll be back on with some more people. We're working here on the platform.
We're very excited. And, uh, you are, you're headed in the van on the way. Well, you're going to Barcelona, then Milan, with a lot of stops in the way.
Yes. W we'll catch you on the road for the next episode. Will do.
Thanks Alan. Thanks everybody. Hey, Yvette, thank you.
Thank you all for watching. I hope you've enjoyed this. This is the platform engineering show.
Do check it out, uh, on your favorite platform, uh, platform, not Plat platform platform, your favorite podcast platform, apple, Spotify, whatever. You can get it on Text Drunk tv, or any number of places online. Until next time, though, is Alan Shimel and Luca Galante for Platform Engineering Show.
We're out. Hi everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech.
I'm Jodi Ashley, executive producer here at Techstrong, here with my co-host Tracy Ragan, creator and CEO of Deploy Hub. And in her spare time, she does a lot of work with the Linux Foundation. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Techstrong.
com. Be sure to go check it out. I'm launching a series to go along with it on texturing TV with webinars and, um, biweekly episodes.
So you definitely wanna tune into that. We're gonna, we're getting that rolling in the next, uh, two or three weeks, so it should be ready for you when, after you see this episode. Uh, we have virtual events coming up.
We're gonna be at CubeCon in London, come, uh, April. So if you're around, be sure and check in and say hi. And if you're interested in doing an interview, reach out to Text Strong and, and we can hook you up with that.
com, and be sure to tune in every day to Textron TV for all of our great shows and interviews. All right, Tracy, what's on your mind today? Well, I think I would be mistaken not to say that, uh, deep Seek is on my mind.
Uh, and in particular, you know, if it's true, what they're saying about Deep Seek, and they have a, they, you know, they have a different way of building these models, and couple of university students with $6 million was able to do it. Um, we won't talk about, you know, the, the, um, the, the, the funding that went behind them, and if they shorted, um, Nvidia, that's a, you know, an interesting topic. But the, the, the really, I think the lesson learned here is we're always disrupted, right?
We're constantly being disrupted. And in this case, if what they're saying is true, um, it proves that our current VC model in our funding model for companies is not working in the us. Uh, SoftBank just announced there and talked with OpenAI to do a $40 billion round for OpenAI, which means that there's a lot of money not going to other smaller companies that might be able to disrupt ai.
Now, I understand that they're in there to make money and they're trying to build up the biggest company that they possibly can. But funding is a, a limited resource. It, it's not infinite, right?
It's not, there's not just this infinite amount of money, um, that's coming through the channels that people can get. When 40 billion goes into one company, it's at the risk of maybe losing out on a company that's small, that may have a great idea and that may be able to build something better. Uh, and not always, you know, spend a whole lot of money doing it.
I mean, $40 billion is a huge chunk of cash. So I, I have to use the term, the democratization of VCs, right? If we're not looking, and we're not, if we're not really doing the research that we need to do, and we're just saying we wanna put as much money behind the guy that we think is gonna make it work, I think we're missing out.
So, that's my thought today, and it makes me sad. Yeah, it's been a big topic, I think, and I think it's brought, been brought up on every episode of Textron Gang this week. So it's, uh, it's definitely a big deal.
Sorry. Um, well, I am excited to introduce our guest today, um, Carolyn Nash. Carolyn, tell us a little bit about yourself.
Hey ladies, thank you so much for having me Today. Um, so my name is Carolyn Nash. I am the Chief Operating Officer at Red Hat, and I know you two are big fans of the open source world.
And so, um, you know, excited to be here. Um, and, and part of Red Hat, you know, which is, which is really founded on open source principles. We, we develop, and we, and we, uh, support open source software that fuels, I think it is 90% of Fortune 500 companies.
So, um, at any rate, it's a pleasure. Just a little bit of it out there, right? So, Carolyn, I really wanna first start this question off, you know, what are your thoughts about the, the potential of deep seek?
And is it really going to disrupt what we thought we had a future in building these massive AI data centers, you know, where, you know, from a, you know, from a personal point of view, not from a Red Hat point of view, where do you think this thing's going? You know, is this just really gonna disrupt how we see AI and demystify it? Yeah, it's, it's a great question.
And I, I mean, I have be honest, I feel like every couple of weeks or something that that is like, we didn't see that coming. I mean, right? Like, AI is changing at the speed of light, and what we knew a month ago is different from what we knew six months ago is different from what we knew a year ago.
So Lord knows where this is gonna take us. Um, but it is disruptive. Um, I think there's no question about it, but I think it's more of a question of what do we, um, you know, companies in the United States, other companies do about it?
And does that fuel a new, I mean, I loved your point about VCs, right? Like, does that fuel a new app? Like, don't rest on our laurels with ai.
We have to continue to innovate and continue to think about how we can do this, and we can do this energy efficient, we can do this cheaper, we can do this faster. And, uh, but it, it, it will disrupt. But I, uh, believe, and I'm gonna take the optimistic, uh, stance on this, that, that, uh, that our companies are going to react and, uh, and come out even stronger in the end.
Well, let's hope that is the case, is, you know, and now let's talk about it from a OpenShift perspective. Mm-hmm. How is OpenShift adapting to these AI models, and how are, what are, what are you seeing from your customers in terms of what they're asking for?
Yeah. Well, I'll tell you, I'm gonna speak in terms of, uh, uh, uh, open shift's number one customer, and that's me. Um, so, you know, it's, I think about Red Hat technology.
I mean, I've run operations, so that's including, you know, including it. And, and we run with every single, every single Red Hat product and, and many of the IBM products, uh, for reference point. But, um, as I look at it and I look at OpenShift ai, um, we're in a position where u we're using it.
We're, we're no different than any other company as we're looking to do things faster, cheaper, um, safe safely. And so with OpenShift and OpenShift ai, we're building, um, models and we're using them to change the way we run our business internally and how we support our customers as well. And we're not only, you know, using LLMs of course, but we're taking on something that's looking at smaller LLMs.
And so basically we're taking them and creating a number of smaller LLMs that are really fit for purpose for what we're trying to use internally. And that is all powered on OpenShift. And, uh, and the benefit of that is it really does address things in a faster, cheaper way.
You're, you have to use less energy, you have to use less power, less GPUs in order to tap into these, these smaller models. And that's exactly what we're talking about with our customers. 'cause again, we're, we're sort of our, our, our customer number zero, we call it our Red Hat on Red Hat.
And, you know, from a, uh, from a security perspective on LLMs, I always felt that having those smaller models and having do models that have domain expertise, and if you can build a multi, uh, a a, what do they call a multimodal LLM system where those are passing information to them, there's, it is almost a way to encapsulate it and, and protect it better, right? Right. There's a better, it is easier to do security around a small LLM than a, you know, I don't know, a 40 billion parameter LLMI don't know what they're opportunity, but Yeah, exactly.
That's So huge. Yeah, That's exactly it. And you think about, like, so say, like, let's talk about like internal support for any given company.
You know, if you have something that's going in and, and you need whatever, I'm an employee and I'm trying to get some HR information on myself, right? If you think about safety and security and personal information, um, you wanna make sure you have a small, large language model that's really focused more on those, you know, HR type of topics as opposed to, and gets routed to the, they ask ar you know, ask hr, um, uh, support desk rather than being routed over to help me understand this customer contract and the terms and conditions on this one. And so it, it not only makes it work more efficiently, but it protects our data better.
And, and with the regulations and, and so much that we have to protect, it absolutely is a safety mechanism for us. Kind of interesting that we, and at the same time that we're talking about building Kubernetes decoupled architectures and getting away from the monolith we, in ai, it's all monolithic. Oops, are we, you know, sometimes I think that we don't listen to ourselves with what we're saying.
So I think it's, I think that model will be more interesting for enterprises to have small LLMs. Yeah. Yeah.
That's, but then we have a lot of agents, aren't we? Like, you know, I'm, I do not like the idea of agents because I think it complicates the stack quite a bit. And I understand that maybe we can't do it any other way, but there are other agents in the stack that we may not need.
And I feel like there's quite a few, there's quite a bit being thrown into production, even to do security scanning, opening up a container in production to see what open source packages were used, maybe some of that we can start scaling back on and pulling from the, you know, from where it was created at the DevOps pipeline and start building more intelligence into that and have a DevOps LLM. Why not? Right?
I love it. I love that concept. Yeah.
We do have to scale back too, because you mean, you think of it, it's, um, you know, you can build and build and build and build, um, but if we're not using everything we're building as well, I mean, we gotta do a little bit of cleaning, like cleaning out your garage, right? Like every now and then, you gotta go in and you gotta pull everything out, figure out what you're not using, what you don't need anymore, and then put it back into the garage, all organized and, uh, available for greater use. And you know what, it takes companies so long to do that, and they fight it and they struggle with doing it.
It's like, talk about hoarding mentality. Yeah. And, and it throws, you know, it creates just this great discussion around governance as well.
And, uh, yeah, because everybody is excited. Everybody wants to try these things. Everybody wants to do these things.
But the more you create, the more, uh, how do, how are we making sure that as we're building and creating, that the experiments that don't work and that we don't want to continue with are actually getting edited back and removed. Um, and it's just, you know, it's almost a, the way it's governance, portfolio management, whatever you wanna call it, but making sure that, um, we're doing that in the right way. Yeah.
I don't think we figured that out yet, especially around security and at all. You know, we have sas, we have das, but we still have vulnerabilities that make it to production, and we're not remediating them very fast. The whole idea of chaos engineering and being able to respond to this, uh, to, to respond to a problem or vulnerabilities, I think it has been underserved and needs to get more attention because it's not really about, you know, root cause analysis all the time.
And especially as we start doing more AI work and we haven't figured out how to secure that. We just gotta get really fast at fixing things. Yep.
You can't prevent vulnerabilities, but you sure can react to them very quickly and, uh, and respond to them, uh, quickly and, and, and, and safely before, um, you know, damage is done. Yeah. So I don't think we could, I talked to our customers.
I'm, I'm in the Boston office where our executive briefing center is, and, and I'm talking to various customers. Security is one of those top things. I mean, cost and efficiency and all of that has always been a topic, but security is, is more often than not something that really has to, you know, they wanna, they wanna discuss and they wanna find out what options they have.
Well, and what I think is interesting is just in the last few years, there was, there was a lot of push and pull. Um, we do a lot of security stuff here, and I would hear these conversations that people would literally argue about, but we should be able to prevent everything. And then everyone else was like, no, we can't prevent everything we've got.
We've gotta be prepared and we've gotta be agile and be able to work through it quickly. And I've seen that we can prepare for everything, just kind of disappear pretty quickly, especially as the AI has kicked in. Um, 'cause that's a tool that helps you respond really quickly, right?
Faster than ever before. But that argument is definitely kind of moved away. We've probably, yeah, no, It's Just not possible.
It's Not, it's not, it's prepared, not possible. It's not you, you can't, you just have to be prepared to react is is what it is. And, you know, And I feel like there's a culture of complacency.
Um, so for example, uh, deep seek gets released and then Wiz goes and says, Hey, we can see that, you know, a ton of data has been exposed. Um, but does anybody care anymore? Does do they, do people really care?
There was even an article I read, um, I think it was maybe it been the Navy or the Army that basically said, yeah, we know we should be watching for vulnerabilities, but if we need to get something out, we need to get it out. And I'll take the risk even if I don't understand what that risk is. But it's a, it's a statement to say we're not doing, we're not serving the community in, in terms of security.
We haven't figured it out yet. And the worst part, the worst part of all this is my opinion is we need investment to get it done. But when you have $40 billion going to OpenAI, there's not gonna be a lot of investment in security or cybersecurity in any way because we've become complacent.
Yeah, it's so true. And I, and I really appreciate your point about taking risks, because I think this is the, the, the balancing, you know, that we everybody's trying to do is how do you innovate at a crazy fast pace, but do it safely and take some risks, but take the right amount of risks in an area that is completely, you know, new to, to so many. And, uh, and, and you know, I think, again, in internally even things we'd, we've created a policy like every company has, right?
Everybody has their AI policy, but it's like version, I don't know what five or six now, because we have to keep changing it. Like, oh no, we, we over rotated and now we're saying no to everybody. Well, no, that's not the right approach, right?
And so then you're trying to tweak it, but, um, you really, you, you really don't know, but you also have to take risks. And, um, but just knowing, knowing where to, to place that risk pendulum is, is really the important point there. I think it's interesting though, how quickly companies, nations have responded to deep seek.
Like, we've let all this AI come and everyone's like, should we be worried? Should we not? Months.
And Moscow, by, I mean, this week, Italy band, it, Ireland, bandit, Congress banneded everybody from the government from downloading it. Um, you know, I think I'm, I'm just interested in, you wonder now if we're just, we flew to the other end of the extreme, but I'd rather see the other end of the extreme. Like Tracy was talking about all this vulnerabilities that people immediately noticed.
Um, I thought, I just thought it was interesting. Every, every couple hours I'm hearing another company or another Com country that says, we're banning it for now. We'll see how long that lasts.
But I just think the response has been, I know, but I think the response has been really quick. Really quick. Yeah.
Yeah. Well, it's culture right now, and, uh, not following rules, not following policy. Oh yeah.
Taking big risk is where we are in our culture. So that's where we find ourselves. However, talking about taking big risk, you know, I was looking through your resume and you've made some big jumps in your career.
Ha ha. I sure have. How did you do that?
Talk to us a little bit about, you know, your background, how you, you know, climbed the ladder to become the COO of Red Hat. That's an impressive job. And it's great to see a woman in that role, right?
Because it's taken a long time for us to get women in C-level positions. Yeah. Well, thank you.
Thank you for that. Sure. So, you know, it's, um, I mean, I started my career quite a while ago, but, um, I, I actually started out in public accounting.
So I was, I was an accounting major in college. Scratch that, I was an engineering major for a bar chapter, and this is, No, I can't, no, pointing is way more up my alley. But at any rate, I, I spent, um, a good bit of time on public accounting, which I absolutely loved.
And I think it became a, a great foundation for my career. Um, because I mean, I love public accounting. It sounds really boring, but the reality is, like what you do when you're in audit is you have to understand how data flows through processes for flows through systems to ultimately end up as a financial statement.
So it, it actually is an incredible foundation for how you learn about how companies make money and build assets. Um, but at any rate, I went into, um, into finance and, um, after I left public accounting, and I was living in Silicon Valley at the time, and so thought tech has got to be the place I go. I wouldn't go anywhere else if I'm living in Silicon Valley.
And so, um, got into finance there and how I actually pivoted out of, of finance was when I was starting a family. And I have, um, I have twins, uh, they're now adults, but, uh, at, at the time I really wanted to continue working, but I needed some more flexibility. So I went part-time and I talked to my boss about it, and he agreed that like, you know, the, the finance and accounting doesn't really offer you that much flexibility.
At least it didn't at the time in the role I was in. So he flipped me into more of an operational role, more projects, things like that. Um, that gave me a ton of flexibility, allowed me to raise my children, and, uh, but also gave me this great experience and exposure to the intersection between finance, between it, between the business.
And I really just loved playing in that space, kind of building on all that old public accounting days. But, um, building in that space. And really from there, it just opened up my eyes to so many more possibilities beyond the track I was originally on.
Um, I got into data and analytics, I got into sales operations, um, and played it. That's Where I saw the risk. I mean, you went from hp, I think you went from, wait, you went from Hp?
Yeah. KPMG to hp, to Cisco. To Cisco and sales operations.
Yeah. I started, it's Very different than public accounting. Okay.
Very different. Seems maybe I'm wrong. Absolutely.
Absolutely. Still got the dollar signs though. Yeah, yeah.
No, it would, my time at Cisco was a wild ride. I mean, uh, Cisco is a great environment to really, they, they allow you, they encourage you to bounce around and try new things and continue to push yourself outta your comfort zone. I actually had a fantastic boss at Cisco, and his point was always Carolyn, when you start to get comfortable in a role, like if you start to come into that little circle of comfort, it's time for you to go look for something new, go take on a new project, just ask for more scope, get something, never get in your comfort zone and never be complacent about your, your, your growth journey.
Um, always be learning and growing and being just at a minimum, minimum mildly uncomfortable. And so it was really at Cisco where I took a, a tremendous amount of risk in, in leaving finance, yeah. Sales, operations, data and analytics, business services.
And, uh, and that I think gave me the confidence when I came, you know, I took a, um, I that gave me the confidence to leave Cisco after 16 years and go to Red Hat. And I thought, this isn't gonna be a new type of company. Something that I was really passionate about.
I mean, 'cause Red Hat's such a cool company, you know, built upon the whole open source communities and development model. It's also an open source culture for me is just been a blast. And, and it's also a company that really encourages you, just helps you open up those opportunities.
And that's where I actually bounced back into finance, believe it or not. And, um, and, and grew my career in finance back up and to become CCFO. And then at that point there was some leadership turnover.
And my, my boss at the time had asked me to take on it and security and a whole other things. I'm like, sure. Right.
Again, you don't wanna get comfortable. And I can't say, since I've been at Red Hat I've ever been in my comfort zone, it's been always right on that outside of comfort, which is how I know I'm at a, a great place. So, um, so I, my, you know, my role as COO, you know, I paused it first, right?
As many of these things, like you got the little, I mean, who doesn't have the imposter syndrome? The little person sitting on your shoulder talking in your ear, like, Carolyn, you're not technical enough for it. Well, you know what?
I don't need to be technical enough for it. I need to be a great leader who can build super smart people around me who are willing to explain things to me, teach me, um, allow me to ask the right questions and dig into an appro appropriate amount of detail to make sure that I am driving the business forward in an aggressive and, and also safe way. So yeah, You need to do a TED Talk and you need to write a book, honey, man.
No kidding. No, it's, you're inspiring to me because it's just, it's just amazing, like your energy and, and just the way your brain works. It sounds like you've had some really great mentorship and bosses along the way that have really supported, like, gosh, we don't hear the, they supported me through raising twins story a lot.
No, We don't. I mean, I could go into a lot more, but I, I mean, I've had some exceptional mentors, sponsors, bosses, and not only had they, um, we got me through my early years with my twins, and, um, but in addition, uh, I mean, my current boss is amazing. He helped get me through the loss of my husband.
My husband passed away two years in the midst of a lot of leadership changes here. And, um, and just really, uh, yeah, I'm, I'm still here and I'm still charging forward. And it got me through one of the most diff the most difficult time in my life.
Um, and it allowed me the space to do what I needed to do and, uh, but also welcome me back and brought me back up. So I, I am really grateful for my leadership and my, my people, my tribe, um, my, my personal board of directors who have I feel like have surrounded me, you know? And that's, um, yeah, it's really, uh, it, it, you know, I'm like, oh, I'm getting emotional.
Oh, What a pleasure. Really Like to have great people around you. That's why I have my energy, because I have great people, um, a around me, and, you know, and Carolyn, I'm so sorry to hear you went through that.
Yeah. Ly thank God you have the entourage around you to help you. We all need that.
We really do. Thank you. Thank you.
I really appreciate that. And, um, you know, and, and, you know, 35 years and most of that in tech, being a female is also, you know, quite a journey as well. And again, I, I feel myself lucky that I've had, uh, you know, a amazing female sponsors around me, amazing male sponsors around me, people who, um, you know, who have just pushed me and, and flick that little imposter off my shoulder.
And, uh, and I also think I've been, I'll get, I'll pat myself on the back to say that I think I choose my companies and my bosses very wisely. And, uh, my choices along the way, and most recently being at Red Hat has been, uh, you know, one of the best decisions, career decisions I've made. I love the open source community.
I'm sure it is amazing place to be a company that it's o an OA company built on open source like Red Hat. You know, I'm, I'm a big open source band. That's why in my, in intro it's always, Tracy does a lot with the Linux Foundation, but boy, open source has taken a beating recently.
You know, we're getting blamed for a lot of security issues, which probably is correct. But, um, we've known this for quite some time, right? And maybe it's open source that's gonna get us out of this problem.
Um, but I feel like there's a lot of stuff being written and we're not doing much with it. Adoption of these security tools and for open source will be a challenge. Um, do you guys talk to your community about, about security?
How do you navigate that? Yeah, uh, I mean, it's a, it's a very important thing. But you know, the thing with, with Red Hat is, you know, when you think about the op open source and, and we, you know, we live and breathe in the, in the open source, but it actually creates, I mean, our whole open source development model is taking these projects in the community, but bringing them and hardening them into enterprise supported products.
And, um, and that's part of the beauty of it. I mean, when there have been some of the bigger, larger vulnerabilities out, um, red Hat's been one of the first ones, and the Red Hat and the Red Hat community has been the first ones to raise their hand and say, we've identified it and we figured it out. Because I think that is the power of open source as you are not only in a enterprise grade hardened product, but you have access to the community, um, that has that, that is using it along the way.
So, I mean, I think it's a benefit. I mean, I'm, I, I, I for sure have been, um, living and breathing it. And, and I, I also, you know, going back to the culture piece of it, I believe, you know, you can talk even more generically about security, and you can talk about security in the enterprise from a non-technical standpoint.
And I believe the open source, um, culture really starts to weed out these things as well. You know, when you are taking ideas and inputs from all different places, you're also getting people to raise their hand to say, I have a concern. And like at Red Hat, even internally, we have company-wide mailing lists where people frequently debate and discuss different topics, controversial topics, but they, things that bubble up that, like we as a leadership team, we're always monitoring it because some of the really like, woo, okay, that's an interesting idea, or that's a really valid concern, or we might need to dig into that a little bit more.
That's open source too. And that's kind of the same, like, you know, you talked about in your personal journey, being able to, to take a risk and staying, staying outside of a comfort zone or just staying just a slightly outside of that comfort zone circle. Um, companies are doing that with open source, right?
There's, they may have, it may be pushing them a little bit, but I'm hoping where it pushes them, they can't get away with writing software without open source that, you know, that cat out of the bag, it's not gonna happen. It would take a lot of coding. It would take a lot of work, and they wouldn't be able to keep up on the, what, what's new in AI without it.
So how do we as an open source community, make them feel okay about continuing to step out of that circle of comfort saying, okay, I'm only gonna use these particular packages, I'm not gonna try to use anymore. I know these are secured. Uh, how do we do that?
How do we bring open source back into conversation that people don't say, oh, there's a security issue with it from a bi from a broad community perspective. I know it's a big question, but Yeah, from a, I know, and I immediately go into it was just buy Red hat, come on. I like, no, I know you're trying to go broad on me.
Um, but that, I mean, but I think that is, it is understanding what is it that you're using it for and is, are you accepting a level of risk in the open source, um, in the open source community that you are comfortable with? What is, you know, a small startup company is different from a governmental agency or a banking, I mean the, I I think it depends on where you are in the continuum, but, but if you're one of these larger companies that's trying to stay, um, and keep yourself more secure than maybe your mom and P'S need to be, that is where you need to still embrace the open source, but make sure it is enterprise wide grade, uh, open source, and that it's, it's hardened and has the security that you need necessary to make your regulators comfortable to make the, the various agencies comfortable. Um, but but open source, um, we've proven that it is secure.
Absolutely. And I, you know, I think more and more, um, some of the tooling that is being developed, open source tooling by the way that's being developed will, will help solve this problem. Um, and I'm hoping that, uh, we start embracing more and more through the DevOps, uh, you know, pipeline, adding more tooling and consuming the data and getting smart about it, because I love open source and I would hate to see it go away, even though I don't think it's going away any, any more than the mainframe ever went away.
And there's legacy open source out there, and there's new being written every single day. And we have to be outside of our comfort zone and start and consume it, because that's the only way we're gonna really build, um, innovation in this country is to accept it. Mm-hmm.
Right. It's just, I mean, it's, it's tied right there with ai. I mean, open source AI is, is an incredibly powerful tool.
It is incredibly powerful. That's just gonna unlock a ton of innovation, I think, unlike anything that we have seen before. What do they say?
This is, this is gonna unlock more than, than, you know, the invention of electricity. Uh, it really will. But, uh, I think, I believe that AI powered through open source is just gonna be exponential.
I would agree. And it's way beyond our comfort zone right now. It is so beyond it, but we have to go there, right?
We, we really do have to go there. Yeah. And, and we have to, I mean, go beyond the, you know, what's gonna happen in six months.
You don't, I mean, you just have to keep pushing the boundaries and pushing the boundaries and, and, and doing what's, what's, uh, you know what I was gonna say, what you're comfortable with, not what you're not comfortable with. But, but you, you can't, you can't, you no longer can do a year long roadmap. A roadmap doesn't make any sense here.
It's gotta be just fast innovation iteration and learning. And again, I don't wanna, I don't wanna lose sight of the governance component of this, um, because it is, um, it, it's something left unchecked could be, could be quite scary. So I know we're gonna, we probably we're gonna run outta time.
Oh, we're good. We're good. So tell us what's new?
What, what's new and what's, what's happening at Red Hat that we might wanna know about or that you can share with us? Is there, you know, what's exciting? Least don't tell anyone.
Yeah. I won't tell anybody. We wanna know what's exciting at Red Hat that the team is super, super jazzed about.
Oh My goodness. Well, I mean, we were just, I'll tell you, we've been talking about it. I, I think the thing that is coming out of our mouths in every single meeting, in every single investment decision, in every single, you know, just, um, interaction we have is, is around ai.
And it is how do we, you know, bring our customers to the next level? And again, I'm looking at how do we bring ourselves to the next level? Uh, but, but doing so in a way that, you know, other companies just haven't thought of.
I mean, we had just had something really cool a couple of months ago. We were looking at some of our models and, um, some of our LLMs and we actually had, uh, somebody from our team go and load up inclusive language, um, standards into our LLMs, right? And so you think about things like that, um, ha just all of a sudden now, you know, something that we were a little bit nervous with about ai, now you load up into those standards.
This is inclusive language and, and all of a sudden it just changes the game a little bit. Um, the other thing that I think is really cool is just skills development. And I think a lot about people and, uh, and where are we gonna go?
And we talked about, we don't even know what's gonna happen in two months, right? Six months a year. Well, we have to assume that every single role we have will not look the same in two years, in three years.
So a lot of people talk about, well, does that mean these jobs can go away? Well, what we believe is we really have to re-skill for, for these, um, for these shifts that are gonna happen. And so we've been creating a good bit of training curriculum and looking at, okay, what are the roles and the skills that we have today?
What are the roles and the skills that we are going to, we anticipate that we're going to need? And let's take that, create curriculum, create experiences, projects, um, innovation days to help people move along that continuum so that they will be ready when we get there. Not if we get there.
And I, I just think that's been really cool, something we're real excited about here. Um, so that, that's just does We have work with universities? Mm-hmm.
Very much so. I, yeah, it's, um, yeah, we have some local partnerships and, uh, so we work very closely with them. And, and I mean, our belief is you gotta go get the great university talent.
Um, they're getting, you know, uh, not only are we importing talent from the universities, but we're partnering on a lot of projects with them while they're in university. Um, and, and investing in that because, uh, again, that's where the innovation is coming from. It seems like the university system can be really slow to put together curriculums and get new classes offered.
Yeah. Uh, I think that's my biggest frustration with, with some of the students that are coming outta university is that they're, they're somewhat prepared, but they're not prepared for tomorrow. Yeah.
Well, we're, we do, um, you know, we have various internship programs where we bring them in, we give them projects, but we, you know, we give them loose projects because what we're seeing out of these, um, you know, university minds is that they can approach a problem in a very different way than historically we probably would've thought. So we do believe in the practical experience, but you know, we've also been investing into those to make sure that it's not necessarily just a traditional classroom experience for this type of innovation. Yeah.
I think we learned that with Seek versus OpenAI, right? Mm-hmm. And was a couple of universities, the students had thought about it differently with the less money and they were just motivated.
Yeah. And we're also trying to get, uh, you know, we are, we are partnering with, um, some of the local high schools and middle schools and, and trying to, you know, just ensure that we are, uh, getting the word out on the importance of STEM to, uh, the younger folks. So we, we often host like middle schoolers coming in here and, you know, we'll do a little pitch on what is Red Hat.
But what we will talk about a lot is just, um, what STEM roles look like in a high tech company. And even if maybe you're not, you know, maybe you're not an engineer, well, still there is a career path for you in stem. Um, and we show them what that could look like at a Red Hat.
And so we break out into smaller groups. What does a product manager look like? What does an engineer, what does a software developer look like?
So that we're trying to also spark that excitement. We give them projects to do that excitement, that sense of innovation at the very early age. And, you know, in, in addition to just getting, um, middle schoolers there, um, we, you know, we focus on underserved communities.
Uh, we certainly wanna make sure that we're getting our young girls really excited about this and that we don't I was gonna say, tell me, reaching out in middle school that really does help young girls Yeah. Maybe redefine who they are and how they could participate in a, in a world where they believe it's dominated by men, which it is. I'm not, you know, we're not gonna deny it.
Yep. It is, it is dominated by men. Um, but, you know, that is, that is shifting and, um, and it is, it's shifting and it's, it's getting better and the environments are becoming more inclusive.
And I feel like, you know, voices are being heard. And again, it's one of the, the, the great things that I love about where I am at Red Hat because that is, we, we very much try to create that environment where you can show up as your authentic self and your voice can be heard, and you can use that to push Red Hat forward. I think men always show up with, with their authentic self.
I don't think they know how not to, 'cause they're, they, they've been, they're allowed to. I mean, they don't worry about putting on makeup at 14. Right.
You know, they don't worry about getting facelifts at 55. Right. They're totally okay.
Oh, they're worrying about that more and more, more than you think. Well, maybe So, but Women all, they're just not as vocal about it. They're not as vocal.
They Not attack amongst themselves like we do. You know, you don't really know that the Botox is going in and, uh, come on, let's face it. It's, it's a thing.
See That macera on there when you, You I've seen the makeup closely, I think. Well, and there's a lot of painted nails, which I love. I think it's fun.
Um, back to the conversation about job elimination. I think when we're talking about these kids, especially college age, I think the incorporation of the AI is what's gonna help. But it's also terrifying to these kids that they hear all this, you know, older folks saying, well, AI is gonna take all of our jobs, and then we wanna make sure we're encouraging them and saying, no, it's not, it's just gonna evolve what they look like.
We just have to push that. 'cause even my kids, they're in their twenties, early thirties, and, you know, we've had that conversation, is AI gonna eliminate all these jobs of our friends and people we know? And we just keep telling 'em, no, it's gonna change what they look like.
We still need humans. Yeah. We still need humans and people who understand AI and, and yeah.
And I, you know, I have two kids in college and that's something that I, I'm like, you gotta understand digital skills. You need to understand critical thinking. You need to understand the way the human mind works, right?
Like, you need to understand these things because these are the important skills that will be necessary in a world going forward that will have ai, you know, it just, it, it looks different and you've gotta be prepared. And it's not just a college, it has to be lifelong learning. Um, you have to be keeping yourself up on this all the time.
And we all do. And, and, you know, you just don't think that your growth opportunity is learning in the job that you have today. It's not, I mean, it is.
Absolutely. Yeah. Uh, so it's lifelong learning and, and pushing the boundaries of those skills that will always be needed.
And we always need good critical thinking. So I'm the one who, who goes off the track here. Um, before we finish, we've only got a few more minutes, I wanna hear about the Elizabeth Nash Foundation.
Oh, Thank you so much for asking Matt. I didn't even see that one. Um, so, um, I mentioned I lost my husband, um, and, uh, he had cystic fibrosis.
He ended up passing away of something else, but cystic fibrosis and his CYS also had cystic fibrosis and passed away. And after she passed away back in 2003, we started up a nonprofit, um, foundation aimed at improving the lives of people with cystic fibrosis. And we, we kicked it off originally with, um, scholarships for people, uh, based on, you know, a whole variety of things.
But people with cystic fibrosis, we, um, uh, invest in research, specific research for it. And, um, most recently we're, we're taking an additional amount of scope where we've created, uh, a fellowship program. And what we're trying to do is, there have been so many medical innovations, uh, with cystic fibrosis that fortunately people are living and they're living longer lives.
But what's happening is other things are coming up that they're, they're starting to lose their life to other things, but they're also aging. You know, it's like new aging issues for people with cystic fibrosis that does not look the same as it does in a healthy body. So we've created a fellowship program where we are focusing on addressing the whole person with cystic fibrosis and making sure that as they age, they have the right healthcare and the right culture within the healthcare to make sure their needs are being addressed and they can live a long, healthy, and meaningful life.
That's awesome. That's great. Thank you for sharing that.
Um, I appreciate you asking. It's, uh, it's been a labor of love and I'm really proud of what we've been able to accomplish and, uh, yeah. More, more great things to come.
And because you've been through it, you have the insight that's needed to be able to create a map of what can help people. Yeah, Yeah. You really trying to take a very patient, you know, a, a person first.
Right? You can start with the medical, you can start with the, the researcher. You can start with this, but we're gonna try and start with the patient.
Right. Start with the human being first. It's, it's their experiences that are really driving our work.
And from what you've told us today, I think it defines who you are. I think you're very person focused. Absolutely.
Thank you. I try to be. Okay.
So before we get cut off, is there a book recommendation that you can give to our audience? Oh, um, So we have a little book club going on in my team here and, um, the one, so we just finished up, uh, think Again by Adam Grant, uh, for all your Adam Grant fans. It's just such a great book.
I mean, we talked a lot about taking risks and thinking differently, and, uh, a great book highly recommended. If you haven't, I haven't read it. Um, the other one by Andrew McAfee.
McAfee is, um, the Geek Way. So that's a really, really good one too. You asked for one, I gave you two, but yeah, I give You one for your book Hub.
You have one? Yeah, we do. It was a book that, I can't remember, one of our guests recommended it, but it's called The Logic of Failure.
Oh, okay. It is really, really good. It is.
Um, what, you know, I read it, the, the, I don't remember who gave it to us. Might have been, might have been. Was it?
No, we always need to remember, we always forget. She said she read it more than once and you know, I just got it on my phone and I read it pretty quickly and then I was like, I gotta read this again. Because there's so much in it, in how the mind thinks and so many good example examples of how the logic of failure works.
It's a really good one, But is like, based on the acknowledgement that failure isn't a bad thing, it's a good thing and that, you know, but how he reactive. 'cause it really Now it's really, um, how we do, how we make decisions, how emotion can get involved in making decisions, how we don't follow the logic as far as we need to, to understand of successes at the end. Okay.
Okay. Kind of similar to the Geek Way, you know, some, some parallels there about Fastest Making Basket. Read The Geek Way though.
I'm gonna, I'm gonna read the Logic. I'm gonna download it on Audible and listen to it this afternoon. Yeah, You'll write it.
This is our question at the end of every interview. So we have quite the book list. I should like compile it Tracy and, and write a, write who, who recommended it for us.
But, uh, we sure put a blog out there. I love it. Updated.
Yeah, absolutely. Well, thank you so much. This was just a wonderful, wonderful time.
Thank you for Well, I know you're super busy and we appreciate you carving out this time to, to join us and, um, I know our audience is gonna love it. So thank you again for being here. We really appreciate it.
Thank You both. This was, uh, this was a lot of fun. Great conversation.
I really appreciate it. Well, we enjoyed having you. It's really insightful and everybody remember, stay out of your comfort zone.
Exactly. Thanks everybody for tuning into another episode of Techstrong Women. Stay tuned for lots more great programming on Techstrong tv.
We'll see you next time. Thanks.