Techstrong TV – May 15, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everybody, GPUs or political ponds, and hey, we might even be tracking 'em around the world you're watching Text on. All right, everybody, as we said, GPUs are in the news again, and turns out that well, there are political ponds and we're using them that kind of set up trade agreements, and there was a whole series of things happening in the world. But we have an awesome lineup of folks to talk about all this.
Starting off with our czar of Silicon Valley. John Schwartz, how you doing, John? I'm good.
How are you, Mike? I'm well. I'm well.
You, you're looking brighter than ever, man. I'm liking this whole new, I'm trying to, I've been working on the lighting, the camera that Alan sent me is very nice. It's a work in progress.
All right. Uh, Well, At least you know, you don't look like you're, Are we all working? So that's good.
We all are. The day to day. Yes.
We're All, we're all a work in progress. There you go. All right.
Well, speaking of a work in progress and a whole award joining us from, are you still in Texas or where are you today? Austin, Texas. Yes.
And we're getting our first triple digit, uh, day today. I am not really mentally ready, but here we are. And also in Austin, correct?
Robert? That is correct. Oh, nice.
Robert is, yeah. 2 liter diesel engines and GPU export controls than I care to admit. Sounds about right.
Well, well, When we and the gang are always excited when we can bring our friends together who live in the same city and have never met before. So it, it happens more often than we care to understand or admit. But hey, it's the world we live in.
And finally, I'm Mike Ard, and I'm here in New York as usual. And we're gonna jump into this topic with John. John.
It's kind of crazy out there. I looked at the entourage that went with the president to the Middle East, and it includes Jensen Wong and the folks from OpenAI, and they were handing out contracts and gifts, like it was, well, candy, what's going on here? And, and, and has this just become the new norm or GPUs being held hostage for training and political Yeah, Like bargaining s**t.
Yeah. The, the, the Trump administration, I think sees these, um, these chips as, uh, literally bargaining chips and, uh, giving them some sort of leverage over other countries in terms of relations with other countries. I think, was it you or someone here?
We, we talked about this, that detect beat has actually become like a politics beat. And in a sense, there were three things that happened in succession, and I'll go back to last week, where it starts with these federal lawmakers. There's one in the house and there's one in the Senate, and they're moving forward with these, these bills that would require AI chips to carry Geotracking technology to keep these sensitive chips out of hostile hands.
Namely, they're talking about China. So there, um, was a chip security act, which was, uh, sponsored or written by Senator Toma Co of Arkansas. And he, uh, wants to keep hardware from quote, falling into the hands of adversaries like Communist China.
And essentially, he would give, the government would give the commerce Secretary authority to verify location of, of this hardware. So then we have that followed by this week's news that NVIDIA's gonna ship more than 18,000 Blackwell chips to Saudi Arabia to help power this new data center project with a newly created wealth fund owned AI startup called Hue, I believe, and who was there in Riyadh, but none others in Jensen, Wong to talk about AI and how it, like electricity in the internet is essential infrastructure for every nation. So they have this project going on.
So this was this project, or this deal was announced as part of this White House trip to the Middle East. And in, in, in the sense Saudi Arabia is trying to enhance its AI capacity and strengthened this cloud computing infrastructure through foreign investment. That deal happened, of course, a day after the Commerce Department officially rescinded the Biden administration's AI diffusion rule that would've placed caps on ship sales to most countries around the world, effective May 15th.
So in a sense, it is a political football, and the can is being handed out to Nvidia and open air, open, open ai, open air, open AI among others. It, it's really hard to, to to, to kind of keep your hands on your grasp what's going on from one, from moment to the other. Um, so I'll leave it at that.
And, um, I would not be surprised if we see even more actions taking place, especially as, as it kind of is a, this part of the strategy of the US to maintain some sort of leadership, or even in their, at our view, the country's view with dominance over AI in its escalating war with China. Uh, Robert, this troubles my free market soul because, uh, you know, basically the United States government is putting its finger on who can buy what, when, and where is this gonna become the new normal? 'cause we could apply this to all kinds of tech.
Well, absolutely. You know, when, uh, when, when GPUs are outlawed, only outlaws will have GPUs. Uh, you know, it, it's, it, we, we've seen this, you know, concerns about export controls, you know, and it worked out so great with, uh, you know, uh, PGP, uh, you know, restricting, uh, you know, uh, encryption technology.
Uh, you can't stop it. Um, also, I think it's a bit overblown, the impact that these chips have, um, you know, know, look at, you know, we just have to point at deep seek to get an example of being able to provide, um, good enough, uh, AI technology on, uh, not the latest and greatest chips. Uh, you know, I I also think Senator Cotton should have taken a trip to Bentonville and, and talked to a large retailer there to see if they are okay with the GPUs that they're consuming, uh, phoning home.
I don't think that they would be on board with that. And also, any technologist will tell you that canceling phone home technology is super easy over the network. Um, I just don't see this getting out the, the way to, you know, implement something like this.
The scale of it is, is simply too big. And, and I just don't see this progressing. I think it's political theater because the Senate's trying to restrict it, but then we have the executive branch trying to do the other thing.
In a previous life, I used to cover the channel and the, we had this area of the channel known as the gray market. This is that whole realm of middle people or middle men or women who, uh, sell all this stuff to folks. 'cause of most of what you buy, you don't buy direct for any vendor.
And a lot of the vendors turn, uh, you know, a blind eye to where a lot of their goods and services winds up. And that's how come suddenly chips are in China that went through Singapore, and nobody quote unquote, knows how they got there, but they damn well do know how they got there. So my question to you, John, is, um, is this gonna upend the whole business model for a lot of these companies?
If we started tracking on a granular level every unit of something should, I was Like, it sounds like a logistical nightmare. Um, you're right. The this, this chain, which is complicated as it is, it's more complicated now than it's ever been, um, in terms of parts where they're coming from.
And then, and then on top of everything else, we have the tariffs, right? Which, which is, I didn't mention, which is another Oli political football involving tech to great extent. So yes, Mike, I think it's, it will be an aggravating, incredibly, uh, annoying, uh, problem.
And I think we're already seeing that. I think, I believe it was a MD and Nvidia were, were performing write-offs in terms of, uh, fracking their, their chips, uh, through all these various permutations. Um, it's, I don't, I can't even imagine what's gonna happen next.
I mean, it's the unpredictability in the, and, and as Robert points out, there's a, that that seeming contradiction between the government, or at least the Senate and the House trying to restrict the, the flow or, or, or not trying to restrict, but trying to keep track of the flow while the White House is, is, is cutting deals with other countries. It's just, it's absolute chaos. And I think the tech industry, of course, I think they're delighted now because in a sense, if you're one of the power brokers or one of the companies with the year of the president or his administration, you are gonna benefit.
We're seeing that already. Yeah. I'll, and this troubles me deeply on this level, right?
So the president wakes up on the wrong side of the bed one morning, and suddenly, uh, my access to AI chips is constrained for some reason, because, you know, he is trying to negotiate something else that impacts me as a company. I mean, how far can this go? I mean, it's one thing, I guess at the central level, but do individual organizations are gonna have to start thinking twice about, you know, who's annoyed at them in dc?
I don't think this is gonna go very far. I, I think it's deliciously naive to believe that the people that are actually making good use of these chips would bewared by these, these lackluster controls. It, it's easily, as Robert said, deactivated, this is something that, that I don't think is, is gonna actually work.
I think all it's gonna do is anger people. Um, I just don't get how, it just shows us how little our legislators understand what's going on in tech. It just, it just highlights for us, um, that That's always, you know, like that, that's always been the case, Anne, right?
I mean, they just stay fun Mentally, like watch any hearing, right? Watch any Senate herring with any big tech CEO and you're just like, oh my God, you don't get this. You don't get this.
And so if this is the move that just shows me they don't get it, um, because this is not gonna achieve anything. Meanwhile, we're shipping 18,000 Blackwell chips to Saudi Arabia. Woo.
John, you know what interested me as well about all of this? Yeah. Was who wasn't on this trip?
You didn't see, you know, Intel, CEO, you didn't see a Broadcom, CEO. There's a, you know, apple CEO is missing. What does that tell you?
Tells me a lot. I mean, but, but remember during the, the Biden administration, he was in Ohio with where the plant was gonna be built with Pat Gelsinger. Remember when Pat Gelsinger was a, was a guest during I think a state of the union speech?
He was acknowledged, um, Broadcom, no sites a MD none. Yes. Apple seems to be a little bit out of favor.
Um, they're having their own problems with the EU and perhaps with the Justice Department. So, you know, Trump does this. He plays favorites.
Maybe eventually we will see Apple in the good graces. I know we're gonna talk about Apple later, and it's, and it's, uh, in Siri. But I mean, in terms of, in terms of Apple, they got some major problems in terms of Apple intelligence.
We can talk about that later. Um, it's, it's just, again, it's just, it's whoever, whoever has whoever talked to him last, whoever talked to Trump last, maybe Jensen did, maybe Sam Altman did. They were front and center and got the rewards.
I think if I ran the reports correct, Jent got some, some candy out of this too, though. They got a, a small portion, a small portion of this deal was allocated their way as well. So I'm not sure they were on the trip, but they got something out of it.
They weren't there, but yeah, they, they, at least they came away with something. I, I just, I always feel badly or for Intel, just, it's just such a long, slow decline. And, um, again, they're left on the outside.
Mm-hmm. Robert, what's your best advice to folks then about all this? I just ignore all this political machinations and carry on is normal, or is there something I should be worried about?
Well, it depends on what your goal is. I mean, if your goal is to maintain solid mental health, yes, ignore it all. Uh, you know, if, If your goal is to make business decisions, um, then, uh, look, I do believe, um, that, um, access to chips is a bit overblown.
Um, certainly, um, you know, there are, uh, quite a few things that you can do with older chips. In fact, you know, with, with my, uh, uh, RTX 30 80, I'm creating neural networks with, uh, you know, for image classification, just fine. You know, with, with my Lego brick sorter, it's not a problem.
Uh, if you are trying to build a competitor to, uh, chat GPT, okay, you're gonna need a little bit more. But for most of the AI tasks that businesses are going to be working with, um, you're okay. You don't need to go and get the most expensive stuff.
What you do need to do is get some outstanding experts that are gonna focus on tuning that model for the hardware available to you, no matter, um, no amount of export control is going to change efficiency when it comes to software in creating models and tuning them. And, uh, you know, uh, uh, mother is, or I'm, I'm sorry, the, uh, mother of invention is necessity. That's why we saw deep seek.
That's why we're seeing the acceleration of open source, true open source, um, models that are driving value. I think a lot of this stuff is political theater. Um, and for mental health purposes, and also for business decisions, I don't think it matters.
And well said. Yeah, I got this one thing here. In my experience, and looking back in history, every time you attempt to restrict something, you wind up seemingly creating increased illicit demand for it.
So am I gonna see GPU smugglers now? And, you know, Absolutely. I, I knew people that were smuggling PGP binders, and, you know, I used PGP in college.
Yeah, I remember. That was a thing people did. And they were like, I'm gonna tattoo it, and then they can't tell me I can't travel with it.
It's just, you know, don't, don't sweat the small stuff. Right. And, and when you do, you make it a bigger thing.
It's, and by the way, we still don't know how deep what chips deep seek was developed on. There were rumors that they had snuck in better AI chips. Mm-hmm.
But, but that was never substantiated. There's no proof to suggest that deep seek required all that work required these amazing chip sets. So we're also just sort of assuming this is a hardware race, when really it's not, it's not that simple.
Mm-hmm. And I'm reminded of those days when, you know, I was in college and the house would get robbed and the stereo would be gone. And now if you get robbed, the GPUs are gonna be stolen.
Right. Catalytic converter GPUs. Yeah.
Yeah. Just the idea of restricting all this, if, if you think that this is a good idea, then just hang out with, um, you know, your, your average middle school students and ask them how they get access to vapes. Uh, I, I think if 12, 13, 14 year olds can get access to that, um, we're not gonna stop this.
I, I do wish they would apply this technology, phone, home technology to, um, uh, prescription opiates, uh, that, that I think would've had more positive impact to the country. Uh, but, you know, who knows if they wanna restrict, uh, GPUs? Great.
And it Also given, well, yeah. The TikTok ban. Look how well that worked.
Yeah. Yeah. I was gonna say, given the ineptitude of the, of the federal government, that these, these, these bills are probably not gonna go anywhere against the lobbying of big tech, especially Nvidia, which seems to have the year of the administration and everyone else.
I don't think it's ever gonna transpire. Right. I will tell you one thing that will happen for sure, though, there'll be more GPU hoarding than ever.
And people are just gonna go out and buy these things and shove 'em in a closet just in case. 'cause nobody knows what's going on. And that's been going on for a while.
A lot of these GPUs organizations are buying, and they're not actually using yet, because they're like, well, we never know, but at least we get 'em why we got 'em. Hey, Well, I cannot wait for the inevitable Beanie Baby, like, crash for GPUs. That will be wonderful.
Mm-hmm. It's true. Oh my God.
Those are called AI accelerators. And they'll be available in a store near you. I minute, I, I can't Wait to, to run my old crappy games at the highest GPU settings.
Can't wait. Mm-hmm. All right.
Awesome. All right. We're clearly not taking this too seriously, but folks, keep an eye out, 'cause Well, you never know what'll happen.
We'll be back in the middle. All right, folks, we're back. And we're talking about Pope Leo the IV from newly consecrated, and one of the first things he said was that AI for ethical use is a good thing and that we should investigate more of this and maybe apply it more broadly.
Uh, first thing that comes to mind, of course, me a former Alta boy, I'm like, well, you know, that pre shortage might be a lot less if everybody just used ai. So who knows, maybe we'll have an AI sermon and a delivery and I don't know, maybe you go to confessional and does it count if you confess your sins to an ai? I don't know.
But John, what's your take on what's going on here? Will this become the new norm in other religions as well? Uh, I can't speak for other religions, but I, I think in terms of the Catholic church, um, this has been discussed.
It's been a topic, it's been gaining traction the last couple of years. I remember doing a story here for digital CXO, uh, when the late Pope Francis, um, talked about the same type of framework. He said that while technology contained the potential to serve humanity must be used ethically, and he talked specifically about how the inherent risks of AI and other things must be mitigated.
I also remember, I believe it was in 2024, he addressed a G seven session in Italy on the subject. And he, he followed up with a speech, um, at the Vatican on, on something called generative artificial intelligence and Technocratic paradigm. Um, there was also a, a study done between the church and Santa Clara University.
I, I wanna say it's a couple of years ago in which they came out with a pamphlet in talking points about the technology. So they are ser they are taking it seriously to a certain extent. And I think it's kind of a continuation.
What Leo is doing is a continuation with what Francis did in terms of kind of, i i talking about things that are, that are not these old age old institutions. I mean, they're talking about current events, whether it is technology or whether it's political or cultural, and they're kind of entering the, the current world versus the kind of old state approach. So I think it's, I think it's encouraging and perhaps maybe other, uh, religions will follow suit, who knows.
But, um, there's a continuation of what Francis had, had, had started and kind of kick kickstarted the last couple years. Mm-hmm. And is this just another form of AI therapy we've seen that kind of evolve over the last couple of years, and it's being more widely used, and you could argue that religion is a spiritual experience and much like there he can be.
So is this kind of on the same continuum? Yes. I, I would say to some degree I think that, you know, this is a new Pope.
He's trying to relate to people. He is letting us know who he is. Um, I actually recently had a friend confide in me that she had been using chat GBT for therapy.
Uh, because she said it, it didn't feel like it judged her. Uh, also FY she's Catholic. So coincidence, I don't know.
Uh, I told her, you know, you could tell me anything. You don't have to rely on Chachi, BT we old friends. But anyway, so I, I do agree that this is just, you know, maybe he sees it as a way to uphold spiritual principles.
Maybe it's a continuation. Um, maybe you, you know, the leap of faith you take to be religious is, is akin to the leap of faith you take to seeing AI as a meaningful thing in your life? I don't know.
Uh, for me it's a logic driven decision, not, not a faithful one. So I, I don't know, but I think, I think it's just him letting us know who he is. I think that it's the church playing global discourse in a conversation.
There's over, I think, a billion Catholics in the world. Um, and it's a green light. It's a green light to say, this is okay.
Um, and hey, go, go have fun with this. And maybe it can help engage people in the church in a different way. I mean, that could be interesting.
Mm-hmm. And if it helps people, why not? Why not?
There's a shortage of therapists. People can't afford them. You know, if it makes you feel better, do it.
Yeah. Why not, Robert? Do I have to worry about a deep fake taking over Pope Leo the 14th here and kind of fooling everybody into doing something they shouldn't be doing?
Um, I, I, I, I doubt that. Uh, look, the, the, the real po the, the real purpose I, I think of, of what he was talking about, his hope was to, um, start, continue that conversation about ethics and ai, um, and, and how we, uh, use these new tools. Uh, it, look, Catholic Church has been around for a while.
They've seen quite a few ways of technology. And, and this is nothing new about, uh, uh, focusing on, you know, uh, dignity and, and, and justice. You know, this, this is always a push for, for all religions.
Um, you know, I, I do think that there is an opportunity for companies like O OpenAI, which is a B Corp, which was set up to really do research, uh, and exploration of, you know, ethics in ai. That was the hope and dream. And, uh, we're really not seeing that there.
There's a big rush into, uh, what we can do with AI and, and pushing the boundaries for this. And, and I'm reminded of, you know, a, a line from Jurassic Park where, you know, we were so focused on if we could do it, we didn't question whether we should. And I do believe that focusing on is, you know, how are these models going to affect the lives of people?
Uh, are we going to start using AI to make decisions that impact people's lives? Um, college admission, uh, uh, you know, credit worthiness, those sorts of things. Uh, um, what about if it starts creeping into our, uh, legal system and criminal justice system, uh, is that gonna impact sentencing and those sorts of things?
Uh, we need to be very careful of these things. And I think that that is what, um, the Pope was bringing up, that there is an impact on individuals with ai if we just blindly say we were gonna turn over decision making to the model. Yeah, I think they're trying, they're, they're, they're trying to get ahead of, of what AI can do, both good and bad.
And I mean, I think that's what the government's trying to do, too. I mean, it's the one technology where people are fully engaged. It's the one technology I, I've experienced or covered where everyone seems to have an opinion.
And I think right now what they're trying to do is position us to think more about the repercussions of what, what it can do and what it can do to us. Yeah. I mean, it could get a little outta control, right?
So suddenly you're referring to an AI agent as a father, and then maybe ultimately it gets promoted to Monsignor, and before long it's a bishop and a cardinal, and it's electing the next Pope. So how far do you want to go? I do believe this is how, that's the beginning of Terminator, right?
Uh, that, that's how it started. I, I don't know. It's been a while since I've seen it.
It, it, I don't know. I guess, yeah. I, I think they'll have to put a clause in there that says, you must be a a, an actual breathing human elect, the next boat.
But I'm sure somebody will get around to amending whatever the rules are. But I mean, don't, don't you think that a lot of the things that are being said about AI now, like, oh, it's gonna destroy your ability to think and oh, it's gonna make us dumber. Weren't those same things said about the internet, about television, about radio?
I mean, how far are you gonna go back the, these sort of naysayer comments don't really feel new to me. It's true. You know, people bemoan the fact that our kids can't read analog clocks, and they look at us and go, well, who cares?
I, I got the time on my phone. So, you know, we Hand a map, hand a paper, yeah. Hand a paper map to someone, to a Gen Z and see what happens.
Yeah. Right? Mm-hmm.
And is that a bad thing? Is it a bad thing that, that they, you know, have tools that are faster? I don't know.
Um, unless you're a survivalist, is it really something that's gonna come to play? I don't know. I think it, where it, it concerns me is the lack of critical thinking.
If we're outsourcing our thinking, you know, do we not get dumber? I don't know. Or do we get smarter because we're not spending our time on repetitive processes?
I'm hoping, I don't know, but I'm hoping for the latter because, you know, at the end of the day, a lot of the rote stuff that we all do tires you out. We are humans, and we spend, I'm hoping that we're gonna spend more time on the things that matter versus Yeah. I don't know.
That's, yeah. Loading store, loading stories, that's Whole point of ai, right? Is to the whole point of AI and AI agents is to move away from road tasks and be more of a critical thinker, or be, or somebody who thinks kind of outside the box.
I mean, that's the purpose. We'll see if that at leads to that. I'm hopeful.
I don't think outside the box, because there is no box. I don't recognize any box that limits me. Oh, I Like that Ann rejects the concept of a box.
I like it. Wow. No box brand.
No, no. I am not imaginary. No imaginary constraints for me.
I'm a free thinker. Um, I will say I've hired recently, and anyone who has hired in the last six months is getting a flood of AI cover letters. And so I didn't require a cover letter, okay?
And so I get these cover letters, and there's all the telltale signs, m dashes, overly flowery language. Oh, here's a couple specifics sprinkled in. So you think a human wrote this?
And so I asked people, I said, today I write this. And alarmingly like, people denied it, people denied it, and the one that didn't, and said, yeah, of course I did. I thought it was a, a better use of my time than, than writing a cover letter.
And I wanted to stand out. That person went to the next round because I appreciated that they were honest about it. I don't mind if you use ai if you're saving time.
I just mind the, the deception. Mm-hmm. All right.
Well, I'm not quite clear exactly how all this is gonna play out from a religious perspective, but I would say that the more time we have to ponder maybe the right and the wrong of things, the better humans will all be. How about that? I, Amen.
All right. Bless you, my son. All right.
And, and, and we'll be back with the next reading in the gospel in a minute. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, well, we're gonna shift gears a little bit, but you could argue that what Apple has been up to is now officially a sin, but, um, they are now determining how much cash to hand out for folks that, uh, apple got busted for eavesdropping with sir on folks.
And they're not the only tech company that's been having this issue. But Anne, let's start with you. Are we gonna see more and more of these kind of payouts for violating people's privacies?
Because it seems to me that this is rampant. Well, we're used to seeing it in the eu, right? But we're not as used to seeing it in the states.
I think that someone somewhere calculated on a spreadsheet, we could keep fighting this, or we just pay it out. And this is, this is chump change to them. $95 million to one of the richest companies in the world isn't really much.
So they settled that, uh, class action lawsuit because Surrey inadvertently recorded users private conversations, which I think we all knew was, was happening. And it claimed that Siri sometimes activated unintentionally and captured sensitive discussions, uh, that were later reviewed by third parties. It was a very ominous sort of, uh, email that I got, and anyone with an Apple account got yesterday.
Um, I would say that the $20 payout is probably not worth my time to go and pursue and prove. Um, but I do think that it was interesting because the same day news broke that they are working on a brain computer interface. Uh, they want to control phones from their brains.
I was more interested in that than the lawsuit. Uh, and then I was thinking, wow, that future lawsuit for, that the brain computer interface is gonna, is gonna just blow this out of the water. Um, but I do think that they managed to not really cop to what happened.
The language was very vague. And I think that it was just a write off. I think it was a write off to move on and go back to business as usual.
I doubt anything will change. Uh, apple is viewed as the white knight in this, in, in this, uh, privacy battle for a lot of reasons because they've marketed as such. But this shows us that they're just like everybody else.
Mm-hmm. Robert, is it me or am I getting paranoid? But every time I turn around, I seem to feel like I'm talking about something with my wife or whoever, and then suddenly on some device website or whatever, I'm being treated to something that is almost spot on that topic.
Um, well, it could be you are being spied upon, or this is confirmation bias. Uh, it, what are the It could be either one. It could be both.
Uh, I have no idea. I will say this. 75, uh, million devices.
Um, that's not a lot. Uh, it's, it's thi this, you know, uh, you can do five devices and get a hundred bucks. Hmm.
Okay, I think I could fill out a form for a hundred bucks and I absolutely have more than five Apple devices, but also 95 million for a treasure trove of data of voice. Uh, what a bargain. What a bargain.
Uh, and, and, and you know, it, this reminds me of certainly the, um, Google went through this where they were, um, uh, capturing with maps, uh, when they were getting all of the street view data. They were capturing a bunch of wifi information and they said, oops, my bad. We're, we're, we didn't mean to do that.
Uh, but really didn't get a lot of clarity on what they did with the data afterwards. Um, and, and so time and time again, people will, again, you know, these companies say how much, you know, and very insightful. It it, how much does this cost?
What, what's the, what's the ROI on this? Oh, we're coming out ahead. Great.
This is cost of doing business. Um, and uh, I don't see this as really much more than, uh, okay, let's make this go away. I don't see this really significantly changing corporation's behaviors on how they do this.
Uh, a lot of this stuff seems to be, um, it's better to ask for forgiveness than permission. John, is anybody talking about this in the valley? Is this a concern or is this kind of just you?
Um, It, it, it kind of unders, yeah, I mean, it kind of underscores two things about Apple. Um, but one, as you said, it's the white, I think Anne said it's the white knight in this whole battle of a privacy. Well, the Dark Knight is obviously meta, but I think it brings up two things.
First, there's that little $95 million, by the way, is nothing to Apple slap on the wrist less than that three over $3 trillion they have. Exactly. Right.
I mean, nothing, it's a nice investment, actually. But what it kind of brings up to me is the, the one story we, we hear about Siri in about anything AI related with Apple has got this little kind of minor negative tinge to it. At the same time, we're reading about everybody else hurdling ahead of Apple on the AI race.
And I, this, I kind of, I wanted to bring this up because I've talked to at least three people in the last couple of weeks, and who used to work for Apple, they used to work within the Apple intelligence arm of things. And they all told me they resigned because mainly out of frustration in this idea that Apple's pretty much, it's pretty much an aimless flawed project. I think even Warren Buffett has, has mentioned his, his, his mis his his misgivings about innovation in Apple, this current state.
And I think it just kind of re it's, to me and to people out here, it's kind of a reminder of Apple, kind of, kind of fumbling its way around AI so far. I mean, I'm not saying they're gonna fail, but there is a genuine concern, especially among the ex-employees who just left with throwing their hands up. I would tell you what I would like to see though, is instead of you sending me an email that says I qualify for 20 bucks, can I just check a box that says that give my 20 bucks to some charity somewhere, then we can all set up.
'cause 95 million to a particular charity could make a big difference. Is that legal feasible, Or It's a good question. Make sure, sure.
People could set up a GoFundMe and then give 10% of that to GoFundMe. But, um, which is why I don't, I don't like those. So, and what happens to the 95 million if only 30% of the people actually go bother to claim their 20 to a hundred bucks or whatever it is?
I don't know that it's all gonna get claimed because it's a little tedious for 20 bucks. Right? Right.
Um, I'm not gonna do it, you know, So does that letter our Primer? Yeah, They, it, it will, you know, they're off that top of that. The, the settlement amount, uh, for the attorneys that did did the class action, they're gonna get their fee that's been negotiated and the, um, the rest of the money goes through a clearing house.
If it is not accepted at a certain point, it is return to Apple. Wow. So, so maybe We should do it just to, How much should we spend that, you know, this 95 million actually shows up in the people who were allegedly victimized maybe 10%.
Right? Look, I'm, I'm gonna do it for a hundred bucks. I mean, and it's gonna take me five minutes.
I would forego all of the money and just to know what the third party was. Got it. And what did they do with it?
That, that's more interesting to me than $20. I, I wanna know what, where it went, because it's very ominous in the language. It just says a mystery third party.
Well, that's, yeah, that's not the deal. And if you wanna find out, don't take the payout and hire a lawyer. Oh my God.
Well, you know, we see these kind of arrangements all the time, right? So maybe, I don't know, can I create an AI agent someday that will manage all my claims that I'm allegedly qualified for? And, you know, I add 'em all up 20 bucks, it turns into real money over time.
So maybe there's a way to manage this so that it's not so tedious and you can have the AI agent direct that money to whatever charity you want. Let's do that. Yeah.
I mean, I, I do think that the legal industry is one where a AI stands to disrupt quite heavily. You know, you've got a lot of old case law to go through. You've got, I mean, and you've seen cases already where people are getting busted, making court decisions and writing legal briefs using ai.
Um, and I think that's only gonna continue. Well, ultimately, we could have probably come to the conclusion that 95 million was the number to settle for if we just used a little AI about last year, right? Yeah, absolutely.
I mean, it sounds good in theory, but then I think, okay, five years ago, blockchain was gonna replace lawyers too. Remember that we're gonna use contracts, uh, on the blockchain and, and buy houses and cars and Yeah. Where's that going?
I, I, I think we'll just file more complex court cases and, and the routine stop will be handled by an ai, hopefully. And we, maybe we can clear up some of those, uh, backlogs and court cases that are holding up the legal system. Uh, so, you know, theoretically it could work and this would just be yet another example of a case that could probably be litigating in an hour, rather than taking how many years to settle this thing.
It's a little crazy, right. John, what's your prediction here? Is this a one-off, or are we gonna see more of these Suits?
Let's see. More of these probably, but, uh, you know, if they, if they continue at this, uh, this rate, 95 million is well worth the investment to kind of, uh, you know, collect data, it's well worth it. Mm-hmm.
And Robert, do I need some sort of way to track what people are doing with my data if they get it, no matter how, whether it's illegally or legally, but it seems like we don't know where our data goes. Uh, you're right. Uh, we don't.
And, and that is gonna be a challenge. Um, there are certainly a large number of companies that are looking at how people can protect their data and their privacy. Um, and companies are certainly looking at how they develop their privacy policies and how they manage that.
Um, you're going to see an increase, um, in consumers being concerned about it. So whether that is hardware manufacturers creating devices that are secure and hold data close to you and, um, on the edge, um, perhaps, uh, but you are gonna see more and more people, uh, especially, um, educated, you know, more advanced users, like the people that are watching this and, and that are speaking here are gonna be interested in this. Um, however, I don't think that there is a big backlash amongst general population on this stuff.
Uh, you just simply look at the rise of social media and remember kids, when the product is free, you are the product. Mm-hmm. And so people have been giving away their data for years.
So there is a large population that doesn't care. Um, there is a growing and significant population that does care. So I do think that you're gonna see people that are concerned about it.
Um, look, everybody should be concerned about data privacy and their data. Um, but I don't think everybody is. So, so lemme ask one more obscure question, but John, if I go in confession and I'm using an AI priest, is that AI priest sworn to secrecy like a regular priest, or can they be called to testify against, He's gonna share it, is gonna share its data with a third party?
That's unknown. I'm being facetious, so I I have no idea. I mean, that's, that's this, the, the whole problem is, is Robert was pointing out, and that's something that Facebook, we always leaned into, uh, this, this, you are the product, and I think there is a TA tested trade off for most people.
Most people are willing to accept that. So they're willing to accept the risk, the, the broad audience, and there are going to be those who will, who will not. But for the most part, the vast majority of people are willing to take that risk and it'll happen.
Right? I think people generally that I've spoken to about it are like, well, I'm not doing anything wrong. What do I care?
You know, and, and apathy is really the enemy here, but I'm less interested in what Apple's doing with Surrey data, which by the way, I assume they were doing, uh, than I am with the FTC case. Uh, and the DOJ plan for Google, uh, the antitrust case, I've been following that very closely. And yesterday the FTC came out backing the DOJ to force Google to share search data with competitors.
I mean, whoa, that data, your search data that getting let loose to other companies is that, is like a way bigger ramification to me than like whatever weird things we've all said to Surrey. Uh, Robert, I'm thinking the next thing thing in home real estate is gonna be soundproof rooms where you can go in there and you, I abs absolutely, uh, uh, Faraday cages, uh, for private conversations, uh, the, the new the, remember we had the conversation nooks, uh, in the seventies, the sunken living rooms. We're gonna have Faraday cages now, uh, uh, in our, in our, our houses.
Um, for, for the, the really hip people have those. Um, I mean, I am concerned about, uh, Google sharing my search history and that getting out because, um, I am a terrible software engineer. And the questions that I have asked, um, Google on how to solve a very simple and easy and chucklehead problems, oh, I'd be so embarrassed if that got out.
And everybody realized what a horrible software engineer I am. Uh, I terrifi, what about all of us that use go to Dr. Google?
I'm not worried about that. I'm, I'm just, my pride, my pride about like, dude, I get it. I guess you had to Google that, you idiot.
Aw, that's what I'm worried about. I mean, if that all that gets released, I think we're all in for some embarrassment. I don't think you're alone in that.
Well, doc, according to Dr. Google, I should have died three times in the last five years. So I'm not so clear that that's really something that I lean on too hard.
But, um, fortunately we have AI search now, right? So you just kind of plug it in and nobody will know exactly what you're looking for anyway. 'cause the AI will know what you're looking for.
And so you can just get all that code that you're supposed to know how to run for free. Are we gonna use search? I don't think so.
I think we're just gonna talk to our machines and then the AI will tell us what we wanna know. The problem is, it'll never forget what you asked, right? All right folks, we're gonna leave in here.
Thanks for watching everybody. I wanna thank our guests for sharing their knowledge and insights. As always, we're gonna have an awesome lineup of Textron TV coming up right after this, and we'll see you guys next time.
Hey everyone, welcome back here to Techstrong tv. You know, I'm really happy to have our next guest on here. He hasn't been on Techstrong tv.
We were talking nine, 10 years perhaps. com, March of 2014 was our first publication. And, uh, those first two years, I mean, when you talk DevOps, it was all chef and Puppet, maybe a little Bil and Jenkins.
And, and Julian was a key key person at Chef, and he'd always come on and keep us informed of what was happening there. I want to introduce you to Julian Dunn, senior director, product management at Chain Guard. Julian, it's a pleasure to see you.
Yeah, it's great to see you too, Alan. It's been a while. Well, you haven't changed a bit.
I've gotten a little Older. Just a little inside joke. We were talking off camera.
So Julian, I mentioned you were a chef, but you know, for people who aren't familiar with Julian Dunn's, uh, life story here, give us a sense of your journey. Yeah, well, uh, as you say, Alan, we got to know each other at Chef. And, you know, prior to that I was a DevOps engineer and a software developer.
Um, but I moved into product management at Chef, and then I took a little bit of a detour too, uh, at Chef. And then from there I went to PagerDuty and did some product marketing for them, uh, for a couple years. Helped to take them IPO and Pager Beauty.
Also a great company, also very, very adjacent to the DevOps, uh, category. Sure. Then I had an incredible opportunity to move to GitHub and help them to, uh, scale the GitHub Actions product.
And I was there for about two and a half years. And as you folks know, in the DevOps community, you know, GitHub actions is, and nowadays it's sort of your predominant CICD, uh, platform. A lot of developers use for that and for, uh, automation.
And then I had the opportunity to come here to Chain Guard, which is a little bit different, but it's still adjacent to DevOps. Um, but, you know, chain Guard is in the, the cybersecurity space. And if you're not familiar with chain guard, uh, chain guard basically is the safe source for open source.
Um, we make, uh, well our first product was, uh, container images that were, uh, low to zero vulnerabilities. 'cause you know, a lot of the containers that you actually download out there have hundreds of vulnerabilities on day one, the ones that you get off the internet. And we thought, how can we actually fix this?
This is actually not a good way, um, for developers to start building things. Um, and so it actually turned out to be really hard, but I love hard problems. Uh, and so I, I wanted to join a company that was solving those hard problems and bringing real value, uh, to, to developers and DevOps engineers and, and platform engineers.
And that's chain guard do data if you're not familiar with us. Absolutely. You know, I became aware of chain guard, I'm going to say four or five years ago maybe.
'cause it really, you know, I I as Cube Con, so four or five years were coming, you know, towards the end of covid, let's call it. And um, you know, all of a sudden this company was like secretariat coming around the, the, the, the curve there for the Belmont Stakes. It started coming on strong.
Everybody was talking about it. And at Cube Con and, and, and, you know, a lot of cloud native, uh, events. And so, you know, part of what my job here is, is hey, you gotta to be aware of these things.
And it's a great story. Of course, you guys, I think announced, was it, was it CubeCon, uh, Europe in London, a a a a huge round? Or was it maybe subsequent to that you guys recently had a large fundraising round announced as well, right?
We did. We, we raised a series D and that was just announced recently. Um, and that's hot on the Gus of the series C that we raised last year.
Yeah. So things are really happening there. Um, actually we're here today 'cause you got a bunch of news you're gonna share with us, Julian.
That's right. Right. I do.
We had our inaugural conference, uh, chain Guard Assemble. And that was a couple months ago. Um, and as I, as I mentioned, when I first joined the company, we had one product and that was chain guard containers.
Um, but we, you know, what it takes to, like I said, the problems that is really, really hard to go and solve to make those zero vulnerability zero CBE containers means that we had to build a whole set of automation, what we call a factory under the hood that continuously monitors a lot of different open source projects out there, figures out which ones need to be rebuilt, rebuilt all the ones on top of it that depend on that one, and basically ship those containers to customers very, very quickly within the, you know, within seven days. There's a critical security vulnerability that's, that's, um, that's found. And then one of the things that, or several of the things that our customers said to us is they started adopting these containers was, well, now that you have this automation, is there anything else you could apply this to?
Look, we have a set of problems over in our, you know, application libraries. These are, for example, in the Java ecosystem. These would be your jars, um, that, that are used as, as dependencies for your Java software or in the Python world.
These are your wheels that you use under your Python code. Is there anything you folks can do to build a product around this? And we looked into it and said, yes, we could, we can use that automation in the factory to, to move up the stack towards developers and help developers be able to reduce, um, security vulnerabilities.
Um, now, uh, in the libraries world, the vulnerabilities happen in a different sort of layer, which is at the build and distribution points of libraries. You go back in the history, you sort of like look at the history of where attacks are coming out. And by the way, you know, you just, you can just pay attention to the news every week.
Alan, I'm sure you touch on this too, but just like every week it seems like there's a security vulnerability in this area. Libraries nine times outta 10 or more frequently and spokes that are trying to attack Maven Central Pi, PI N-P-M-J-S, these distribution points, or they're trying to attack my old stopping ground, the GitHub action and try to compromise that workflow so that malicious content is being uploaded to those distribution points. That's a lot easier for attackers to go after than to actually break into the GitHub itself, that source code.
Uh, because you know, these, those, those platforms, the, the Pipis and the Mavens of the world or Maven Centrals of the world are set up for kind of like the creator economy makes it really easy for folks to, to share and to upload new content there, right? So you get typo squatting attacks and things like this. So what we're doing in Chain Guard libraries is, hey, if the source code is what's hardest to break into, why don't we go back and try to find the source coordinates for all the top, the popular library going back a few years and try to build those from source in the same factory that we have for container images and then offer those in a secure offering to our folks, to our customers.
And we've gotten a lot of, um, a lot of interest from enterprises, fortune 500 companies, you know, folks are looking at this and being like, my, the risk surface here is, is too high for me. I really love that solution, um, of, of, of chain libraries. And then the other announcement that we made, Alan was also, you know, folks saying, Hey, you know, I still have a lot of virtual machines in my, the state in the predominant use case for virtual machines vis-a-vis chain guard is, well, containers have to run somewhere.
They're just not uploaded magic to the cloud. They're still executing on some, some machine. More often than not, that's some kind of virtual machine or what you might call a container host up there, right?
It runs container deed and a bunch of other services and things like that. And we saw what would it take for us to extend what we already kind of know is chain guard os, if you will, and extend it to be able to, to, to meet a, a virtual machine use case. So what would that take?
It would require us to build a kernel. It would require us to build system D and a few other services and container D and these cloud agents and things like this all from source and then ship, ship customers. That virtual machine image that they can plug directly into either a hosted, um, Kubernetes service like an ela, uh, EKS and Amazon Elastic Kubernetes service, or maybe in their own Kubernetes clusters where they're bringing their own container host.
So we announced that as well at at chain guard assembly. You kind of think of that as almost like going the opposite direction in this pyramid in the stack, right? I'm going down the stack more towards the bare metal.
So we, we think we we're trying to protect the supply chain, software supply chain at all levels of the stack. Um, and so we think, you know, with this would, with these two announcements, it's a robust platform that we now have to go and do that for customers. So Before we go into maybe more announcements, let's, let's hit these two in terms of libraries.
You know, I, I recently, I was at RSA conference, I don't even remember, was it two weeks ago or a week? It was two Ago. I was there.
Two hours, yeah, two weeks. Yeah. Where are you at?
You should have come by and said hello. We, we did our DevSecOps thing that we always do, 10 year, 10th year anniversary of it on Monday at, at the Moscone Center. And then I was at, uh, broadcast alley all week, but I was talking to the folks from Sona Type, you talk about Maven and everything, you know, they've come out now I call it a firewall that sits in front of the repos.
And so when you are downloading from the libraries components or what have you, it's actually checking, is it really the what you think it is? Is it compromised? Is it, is it an old version or a new version?
And there are some people who for whatever reason need to use an old version, but you gotta be aware of, you know, the, the exposure there. And to me, this, this was Julian, this makes so much sense, right? I, I don't almost put the onus on every repo library kind of source that hey, you, you have a duty to put a border control, right?
Border controls are a big thing in this world today. God knows, I don't want to go there, but, you know, we should have them at repo certainly and, and be doing something about that. How does libraries play into that at chain Guard?
And then we'll come back to the vm. Yeah, I think, you know, one of the thing things is that, you know, those types of firewalls are useful in, in some ways for signaling to folks. What are the risk levels?
You know, they're using sort of heuristic analysis. You, as you pointed out, there's some type, a few other products out there as well. They're sort of trying to grade things or whatever and use heuristic and sometimes even AI or ML analysis of, of projects and things like that, you know, they are helpful to a certain extent.
Um, what I would say is that, you know, there's a, just the flood of how the, the volume of how libraries versions change. New things are published all the time. Sometimes things become malicious over time.
It's not like the library itself that that author was, was doing anything malicious. But somebody, some, sometimes a nation state actor is realizing the popularity of some library. And then without that author even knowing is going and doing and, and kind of perverting it and changing that library and creating new version that don't exist and uploading them to these repository systems, right?
Um, so the firewall is one line of defense against that. But another line of defense is, let's just go back to that source code again and, and just build it directly from the source code and what the intent of that actual author was. And then you can avoid some of these attacks.
You can avoid these mystery version that don't exist out there that that author never created, because you're never consulting a system in which they publish, right? You're just, you're, you're, you're sort of bypassing that. However, libraries does plug into these systems that, you know, for, for grading, for, for rating, because we have all the build information and the provenance and things like that of what we've done in our build system that can be helpful for folks, you know, using these types of, um, policy and curation.
Well, Absolutely. Let's talk VMs now a second. Look, it's no secret, right?
Broadcom tripled the price of the licensing on some, uh, VMware and right, wrong or indifferent. It's given people pause to evaluate, do I wanna stay on-prem running my own VMware? Do I wanna finally make a move to a cloud, maybe use their virtual machines?
Do I just run a wanna run cou, you know, a Kubernetes kind of on bare metal system, if you will. Yeah. Um, or, or some combination thereof.
Is that driving any of this chain guard VM That is not primarily, I mean, we're, I'm aware, obviously, of that macro environment. I think it's helpful as folks move to the cloud. Uh, it's helpful to, to products that are targeting VM workloads.
It's not really, uh, what, what drove this move? This move, again, I would say was driven by customers saying, look, I still have all these problems with trying to patch my, you know, virtual machine environments. I have, uh, perhaps compliance regulations in my virtual machine environments.
You know, I, I don't necessarily have, if I try to solve these problems, sometimes I don't have portable solutions across clouds. Most customers are multi-cloud today. I mean, surely they have a predominant cloud in most cases.
They have an incumbent cloud, but many of them are running specialized workloads in other clouds. They're looking kind of for one vendor that can help them to maintain virtual machines with very low or zero vulnerabilities, but can also keep current with the necessary software as they're doing virtual machine workloads. So this is like the kernel and container D and all these sorts of things.
Um, so that was the main motivation to try to get into, to get into this market. Right. All right.
So Julian, we covered some announcements at your recent, uh, as you mentioned, first ever user event like that. Bring us up to the minute, what el what else you got for us? Yeah, we're announcing, this is really exciting, Alan, today.
So, as I mentioned at Assemble, we announced sh guard libraries just for the Java ecosystem, and today we're announcing shard libraries for the Python ecosystem. Very, very similar value proposition. Same thing.
We're building Python code from source, which looks a lot different than Java, right? It's an interpreted language. So what does that mean?
Mm-hmm. The building is slightly different, right? It's more like packaging stuff into these wheels that, that get installed by pip.
Um, but we, what we found in the service of doing this, we found there's also some, and we'll be publishing some more blog posts about some of this material in the coming weeks. One of the things we found, um, in the Python world, uh, with libraries, there's a lot of, uh, folks out there that don't realize there's a lot of, uh, C code and things like this that's actually bundled into Python. And a lot of that C code is untraceable.
Nobody knows what the source of that is. Or cus or a lot of folks that are building and uploading these things to the pi pies of the world are bundling a lot of, uh, just sort of like, uh, you know, vendor libraries is what we call right? Shared objects and putting them in their, their libraries.
And that stuff is untraced and you don't necessarily know what the code path of some of that stuff is and whether or not the, the Python code is actually calling into to that stuff. And so, you know, by building everything from source, including these sort of like embedded shared objects of the C code, we are providing full traceability over the Python code that's running in your world, including any of these, what we call native libraries. So I think this is a really exciting, um, analysis for us.
As you, as you know, Alan Python obviously is used predominantly in the AI world. You know, I, I have a personal fear that a lot of folks are kind of rushing to market, would AI products and sort of like security is an after Fun. No.
You think so? Yeah. Well, you know, the way, but the way to fix this, Alan, is for folks to just start left, right?
You have to make it easy for folks to start on something good. If you try to add security later on after the horse has already left the barn, it's pretty hard to go and do that. Right?
That's why scanning alone doesn't solve your problems. And so it's really important for us to bring an offering like this to market, to get folks to start good so that down the road when they're worrying about these things, right, they're secured, they're already on something that's good, right? It's zero friction how we've kind of like made these libraries work zero friction to developers.
It doesn't change the developer workflow at all. We're providing just higher quality substitute libraries for developers to use that are built in our hardened factory environment. And they don't notice a thing when they go and adopt this product.
That is important. You know, unfortunately, Julian, it's an old story with security. Mm-hmm.
Uh, we sort of bolted on after the fact instead of built in from the get go. Um, but, you know, but things, pigs fly and things do change. And, and this is a great way of, of getting ahead of it because I've never met a developer who says, you know, I'd really like to develop some low quality code.
Exactly. They all, they all wanna develop quality and have security. It's just a question of the friction, as you mentioned.
Yep. What else you got for us? Um, well, we also have a couple other features that we announced at, uh, chain Guard assembled that are related to the container.
Um, the container product that I didn't mention, you know, one of which is, again, these are all based on sort of customer requests and demand. You know, one of them is customers ask us in the container world, um, is there more that you can do to help us to customize the images that you're giving to us? You know, and, and sort of, uh, it started with the, I would say the bulk of the requests from customers are very much around, Hey, I already purchased a couple of images from you, but we're not totally microservice oriented yet, so I need to stick a couple of different images together.
You know, I have a workload that's maybe like go and node js or something. Well, I already own those two images with a way that I can kind of compose 'em together. I call it like the mix tape of images.
And we said, yeah, absolutely. We can build the service for you to go and do that. And we call that custom assembly.
Um, and that's something that we have, you know, on the truck today. Customers can use it. Um, and in the future we're gonna be expanding that to other different types of customization that, that folks are asking us to do, um, for their container images.
And that just eases the burden for those platform teams that are trying to fan out, um, and, and have these images widely adopted by, by customers inside, inside the organization. And another thing that we announced at Assemble, which is really interesting, um, and it's also a function of how we're able to do this feature, um, is because we own the spectrum, we control these different components and the dependencies and, and and things like that. Those are a feature called what, uh, what we call EOL Grace period.
And you know, there's a lot of companies that can't move quite as quickly, um, to upgrade everything in time for when software goes EOL and things like this. And we thought, you know, could we extend some of the, uh, coverage in terms of like low vol, lower zero vulnerabilities for some of the stuff we already built, um, to stuff that's going EOL or maybe has already gone EOL. So we thought, hey, we can't do anything.
If the main package, let's say that's engine X or something, if that goes end of life and, and that primary package accumulates some security vulnerabilities, there's not a lot we can do because that maintainer has moved on, decided they're not gonna maintain that anymore. But if there's vulnerability that we can fix from its dependencies under the hood, if we can manipulate the dependency tree and we can bring some of the vulnerabilities that we can eliminate the vulnerabilities that are under the hood by bumping to new versions and assuming that Topal package like Nginx still compiles, then we have successfully kept that image at a zero, at zero vulnerabilities. And so folks can continue to use that.
Now of course they're still taking on the operational risk of running something that end of life, but it just gives them an extra, extra, extra little bump. It's what we call it a grace period for them to get to buy themselves a little time to get off that old version while still maintaining a good security posture. I love it, Julia, for people who wanna stay up on not just Chen Guard technology, but all that's going on, 'cause you guys certainly have a lot going on.
dev? We have a blog there. Um, and it's got product announcements, it's got engineering announcements and things like that.
I did also wanna mention, you know, chain Guard does have a starter image tier. So we do provide, you know, somewhere in the neighborhood of 50 to 60 of our images, the latest versions of them. So it's a rolling version plus that you can experience the value of chain guard and the value of the zero vulnerabilities and the S bonds and the attestations, all that for free.
Um, and then if you want older versions or, uh, you know, other, other software that we don't have on the truck outside of those 60, then the rest of that is, is a paid plan. But there's a way for you to kind of try and experience chain guard's value, um, without having to, without having to contact contact sales. So please check that out.
I love it. People like to check stuff out without having to contact sales. You and I know that.
Mm-hmm. Julian, then it's great seeing you. Now that I know you're here, I expect to have you on here a lot more often.
I'll definitely try to make that happen. Alan, it's good to see you again. Alright, my friend.
You be well. Good luck. You.
Sounds like you guys are running on all cylinders there, so it's all good. Chain guard. Julian Dunn, senior director of product Manager in here on Tech Drunk tv, and we're gonna take a break.
We'll be back with more. It's Tech is text on tv. It's Getaway Day here at RSAC, Lisa Martin here.
Having had some amazing conversations with cybersecurity leaders across industries the last four days. But you know, because you've been tuning in to Text on TV and all of our other digital platforms. My next guest is a veteran of Text on tv.
My first time interviewing her, I'm a huge fan. Kaitlyn Sien joins us. She is at Cybersecurity Girl.
6 million followers across social media. You should be, Caitlin, it's a pleasure to have you on the program. I'm so happy to be here.
Talk to me a little bit about you have amass in a short time period. 6 million followers. I'm one of them.
TikTok, LinkedIn, Instagram X. How did you do that in such a short time period? I, I don't, I don't know.
Um, so I started on TikTok originally and I really was, uh, embarrassed. 'cause I've been in cyber for 12 years now and I'm like, if anyone finds out that I'm on TikTok, I'm gonna be destroyed in, in, in the office. And, but I really wanted to reach the next generation.
That was like the main reason. I was like, I want people to understand like everyone it like is needed in cybersecurity. And cybersecurity is not something scary and they can get in and it can be fun.
And we also need more women. I wanted women to see themselves. Yes.
Because when I was first introduced to cyber, my immediate gut instinct was absolutely no way I'm ever gonna be a part of this. Yeah. I was like, I'm not a man.
Yeah. That's, that's the number one reason I'm not a man. And I was like, I didn't see myself there.
Like, I just was like, that's, I'm not a coder. Like I don't, that's not where I'm supposed to be. Yeah.
And that was like the main reasons why I started. And then I started doing more education on does the general public on like what cybersecurity is and honestly how simple it can be and how it's not scary. It does not need to be scary, but it needs to be like, the conversation needs to be had at home.
And I always say cybersecurity starts at home and it's not a scary thing. It's a, it's a necessity. It's a total necessity.
Um, and so that's kind of how it started. And I, again, I only started on TikTok four years ago and it wasn't until the last two years I put started doing it on Instagram. And the reason why I was called Cybersecurity Girl is 'cause I didn't want my name on it.
So I didn't have my name affiliated with it at all for the first like year and a half, two years. Okay. No one I worked with knew that I was doing it on the side.
And then it wasn't until I got hired by TikTok and then I'm like, oh, now I can actually say it. 'cause they, they found me from my TikTok. They found you.
Yeah. So it's just been incredible. I mean, it really shows how important cybersecurity is now and a hundred percent how people really wanna know.
And the reason why I'm a little bit different is 'cause I, I like Shortform. Like I don't do long form YouTube. I don't even really do XI, it's really just been like TikTok and Instagram and Shortform is for me is so important because people don't have the attention span.
And honestly, even if they did, the general public does not wanna hear an hour long conversation about cybersecurity. No. So what do they need to know?
Like how is it impacting them and how can they fix it? Yes. So like relatable, digestible, understandable content.
And that's what I love to do. That's exactly what's needed. I'm a marketer by training.
I've been doing marketing and tech for 20 years. Media for, for about 10. But people want to be educated in the simplest, cleanest way.
Yeah. And you just hit the nail on the head, digestible, clean. How does it affect me?
Right. You know, one thing too that we're dealing with now is I was mentioning my mom's almost 80 and she's digital. Yeah.
She's a facebooker. She's now an Instagrammer. I introduced mom to chat JPT the other day.
I know. I was so proud of Her. I'm gonna throw my boyfriend under the bus, but he is, he still does not know anything about Cha.
I'm like, I don't know if I can be in a relationship with you anymore. You gotta educate him, Girl. I I I'm Trying, I'm trying.
We're working on it. But we've got like five or six generations in the workforce today that are digitally active. Yep.
And some of those populations are way more susceptible than others. Yeah. So I learn a lot from you in the things that you post.
'cause you make it clean, you make it simple. You maybe go, oh, I didn't think about that. And so I teach my mom a lot of the things that I learned from you because I want her to just be, you have to, you can't just blindly trust everything anymore.
Right. We've learned that time. And again, ransomware is a household word.
A ransomware attack happens. I i the status from a couple years ago, once every 11 seconds. Right.
I'm sure that time is going down now. Right. It's only gonna continue.
But to your point, the education has to be there consistently. Right. Well, and there's two, two points I wanna hit on that.
So the first is, we also always think about our like, you know, older population of like, oh, they're susceptible. But the issue actually is the younger generation. So the older population gets hit with like larger ransomware issues.
Like they have the, the most money, but actually the most people that are getting hacked are the younger generation. Is that right? Because they're so blindly accepting of the technology that they don't think anything of it.
They're not like, meant to be skeptical of it. Yeah. Because that's what they grew up with.
And so it's real. That's, and that was why I was like, let's reach the next generation. 'cause all these people, I mean Yeah.
They're not gonna have monetary value 'cause they can't really exploit kids to point. Yeah. There is extortion, which is a whole nother issue.
And it's like a, it's awful. And we're trying to mitigate that too. But a lot of these kids are actually dealing with similar issues as the elderly, but the elderly have way more to lose.
It's Right. It's the financial it hit. And then the other part is like, similar to what you said, like cybersecurity is a human issue.
Like phishing and like, like reusing passwords. Like again, the Verizon DBIR report just came out. I went on, I went to their session yesterday and they were saying 60% of all of these, um, threats and, uh, vulnerabilities are human centered issues.
So whether you reusing passwords Yep. Or access management stuff, like, and or clicking on a link. It's all like human at the end of the day.
And so that's like what I'm trying to get at. I'm like, I feel like I'm protecting the companies at at this point too because it, the learning has to happen at home. Like, when was the last, last time you learned like, what, what did you learn?
Like last, obviously you do this so you learn a lot, but like when you're at home, like how do you learn, Uh, social media? Yep. So that thing news, everyone is losing on social learning on social media, but I through it with a grain of salt.
Oh yeah. You have to. Yep.
And but, but with deep fakes and the advancement in the sophistication of like phishing, smishing, vishing, it's getting harder and harder to detect. Yes. But I like your tagline that cybersecurity starts at home.
Has To it Has to. It's not a nice to have anymore. This is how it needs to be like a fabric of our lives.
Yep. And we were just talking, I don't know who it was with, but like, someone was like, yes. Oh, I know the founder of the hacking games that we were talking about how cybersecurity marketing has been such, it's been terrible.
I was gonna say a bad word. I'm not gonna say a bad word, but it's been terrible. Like we've been, we've been marketing cyber all wrong, even like companies.
Right. Like cybersecurity is not something scary. It's not like Yeah.
We just need to mar like market it to like, and bring it to the people where they're at. Yeah. And they're like, you know, online just general human beings Right.
That are like, I mean, we connected on Instagram. Yeah. It wasn't because I like met you through, you know, some Right.
Yes. Forum. Yeah.
Yeah. But, you know, so, so it's starting at home. But also another thing too is just the, the commonality of it.
And we have to expect it's there. Yep. With there's more data, there's more software, there's more apps.
That trajectory is just going up and to the right. And it's not gonna slow down. Nobody wants less apps or less data slower.
They just don't, We do want less op uh, less like signing in for accounts. Yes. Can we stop that?
Like why Media? I'm a fan. The fingerprint, I'm like, it's me.
Yeah. Yeah. Hi.
I'm the problem. It's me. Yeah.
But, um, it's just such an interesting Love the Taylor Swift coat, by The way. I'm a swifty. Yeah.
This is why we kinda have nice things. Yeah. I can throw you another one.
Um, but I, I just, I think that it's so important to educate folks and it has to be consistent and, and when we're here at shows like RSAC, we get to see so much of the technology that enables that fabric. Yeah. And now that we're in the AI era, love, I love, how do we secure?
Yes, me too. Yeah. There's so much potential.
Yeah. But there's a lot of fear. And so what I like to do is, let's pull out, and I think you're similarly minded, let's pull up all the positives that are there.
Like, we talked a lot this week about how does software company X, YZ help customers, whether it's financial services or healthcare or automotive, become proactive Right. Against the attackers. Right.
Because technology is neutral. Good uses, bad uses, it's like fighting fire with fire. But it's, there's never a dull moment.
And we need more people like you to educate the different user generations and groups of where the risks are. 'cause they're not going away. No.
No. And I, I also like, love the, I love ai. I think it's the coolest thing ever.
And like anyone that like doesn't use ai, I'm like very skeptical around me too with my, including my boyfriend. I'm like mm-hmm. Um, but I think there's also a conversation that needs to be had around like, 'cause people keep saying like, ethical ai, ethical ai, I am like ethical is like moral based.
Like everyone has different definitions of ethical. Yes. So I guess it's like, how do we build AI and like, like what standard like baseline standards do we need to have to say this is good versus this is bad.
Right. Right. Because we are even talking about that on like hackers.
Right. Like, we're talking about how kids are, we're trying to get kids into ethical hacking versus like, you know, a lot of times kids get like pulled into the wrong thing when they're doing hacking. But we're like, okay, at that point, what's ethical hacking?
Like where is a line? Like can you scam a scammer? Yes.
Yes. Like, is that ethical? Yeah.
Because you're still scamming. Right. But like, so it's the same with ai.
Like how are we drawing that line of like what's right and what's wrong Yeah. And what AI should be doing. And what ai AI shouldn't, And that's so nebulous right now.
Yeah. 0 and this Japanese animation studio. Have you seen those Japanese animations that are like flooding social media?
And so the, I have a very like, narrow lane with social media because, 'cause all I see, like tech stuff Good for you. And because it's, it's for work. But anyways, I did not see it.
But It's, so the whole copyright infringement Okay. Challenge is there and it's like, well, AI and, and you know, chat, DBT anthropic, all of them are te are training their models on all of this information that probably they have without permission. Right.
But how do the models learn? So there are fine lines, but I think the challenge is it's so nebulous. There are many fine lines.
Yeah. So to your point on ethical hacking, where, where are those lines? Yeah.
It's not a, it's not a straight answer. Right. But you also talked about people, and I always say I had this friend by other show who created stickers and needs to have stickers on his laptop.
And one of them said humans Yeah. Ruining everything since forever. Right.
And I loved it. But in cybersecurity, humans are, I think two things. The weakest link, but also the biggest potential asset.
Yeah. Do you agree with that? Oh, for sure.
Yeah. And I always used to say like, you're only as strong as your weakest link. Yes.
With every company. Yes. I'm like, I don't care what what you do, but if you, if someone's clicking a phishing link, it doesn't matter any of the software that anything that you deploy.
Right. So I don't, I always don't understand like why companies don't spend more money on training awareness. Granted, I think there's a lot of, uh, training awareness companies that need improving.
Agree. Um, I, I go to a lot of training awareness conferences and stuff and I'm like, Hey, can we not do another fishing email? You See opportunities.
I know, I know. Yes. Um, there's so many other ways to do it, but, um, yeah, I think there's so many opportunities because again, you're only as strong as your weakest link.
Why aren't you spending more money on trying to like, again, educate the people where they're at? Like, why do we keep shoving training and awareness into, into corporate, you know, employees faces? Oh yeah.
Around, Hey, you need to protect corporate. Why do they care? Yeah.
Why would, why would I care? Yes. Who cares?
I mean, yeah. It's, it might, you might lose your job, but like no one, you have to get to them. Like actually, like the impact, the impact that it matters.
Like okay. How to protect your family. 'cause they guarantee you, once they start learning how to protect themselves, they're gonna start learning.
They're gonna automatically protect the company, which is good. Right. That's The right pathway.
Right. But we're not even teaching 'em like that. No.
Because it's a check the box and then there's like some fun awareness stuff. But it's like me. So how do you, how do you advise companies to change that?
Make it more fun, but to your point, go where they are. Go to their comfort zone. 'cause people don't wanna get comfortably uncomfortable.
Right. It's hard. Oh, very.
It's cultural. Yeah. It's behavioral.
Well, that's how it, that's how I always recommend. I'm like, okay, what, what is, what is your company culture? And if you were them, like I always, whenever I talk about training awareness professionals and people like are wanting to get into cyber, I'm like, you should start with training awareness.
Yeah. Because those is, you are the, the prime demographic people that have no idea what cybersecurity is. Yeah.
And you're trying to get in and you're trying to understand, but like get understand the culture. Yeah. Get someone in that's not, that does not care about cyber, does not understand cyber and start picking their brain and asking 'em, like figuring out how, like how you can relate to them.
Yeah. Um, because that's where you're gonna have to meet them. Yeah.
And then to just assume that most people fall in the middle, but like, you can't, as, you can't like do a check the box training. You Can't. No, because I, when I worked at TikTok and I was trying to redo their internal training too, like I had to get so much oversight from like legal and like GRC.
I'm like, this training is not gonna do anything. Like, you brought me in to like, you know, spice things up with training and make it more fun and do short form videos and, and I'm like, and I can't do any of that with like, the way that you're redoing my entire like, script. That's kind of anti TikTok mindset.
It was, it was kind of weird. It was kind of weird. Yeah.
I love TikTok though. But it's, yeah. What, what has surprised you in the last few years of being cybersecurity girl and, and amassing this following who are learning so much from you?
What enlightens you about the direction that career paths are going? What's out there? That's good.
I mean, there's so many things that are out there that are good. And s honestly, so many cybersecurity people are good. Like, there's so many of us because we got in, like, we were pulled in from other people that we wanna help and mentor and like help other people.
What's um, incredible is like how many people are wanting to get in. That's good. That, and I don't wanna be a negative, but like now we're at this point where I get so many people messaging me being like, Hey, I've gotten this certificate, this certificate, this certificate, and I can't get an entry level job anywhere really.
So whatever they're saying about entry level roles is a load of bs. Okay. So I think a lot of entry level roles are actually mid-level roles Okay.
That are trying to be paid as entry level. And a lot of companies don't actually wanna train the people on site anymore. Okay.
Which is really sad. 'cause that's how all of us learned. Yeah.
I mean, all of us got into cyber. We were brought in by a mentor trained on, on site. Right.
I'm sure, I mean, I'm blanket statementing. I'm sure there's a few companies out there that, but like a lot of the companies I've seen, they have like entry level, well mid-level roles classified as entry level and they want people with actual like more skills. And there's so many people, like I get like at least tens to hundreds of people a day messaging me being like, how do I get in?
No, I don't know what to do. And there's not really a direction yet. So I'm really excited 'cause there's so many people that are interested in Yeah, that's good.
Now we have to figure out as a even like a country or like a the world honestly. Yeah. How we're gonna navigate this because also the, the definitions of cybersecurity are different in every company, right?
Oh yeah. Like everyone has different teams. Like some has access management and they, they, they're, maybe they're doing the same thing.
They're called something different. So like I was trying to work with NIST and say, Hey, is there a way that we can have like 10 of the same exact entry level roles exactly the same or exactly like equal with the what you need. Like, so, okay, hey, we have a so analyst that needs these like qualifications, then we have like a threat intelligence person.
So I want the same titles Yeah. With like clear expectations of what they need to get. And that way, like when people are hiring entry level least make, make the fortune 100 all do the same when they're hiring.
Yes. It'd be a lot easier to transition people in. It would, and then you can train them then on their company culture.
You pick them on their company, your company culture. Right. The alignment Best.
Right. Yeah. So that consistency is, is critical.
It's no longer, um, a nice to have that the, the awareness has to be consistent. Right. I've been, like I said, marketing 20 years in tech awareness is key, but it can't be a one and done thing.
Right. And it has to be tailored to your audience. Right.
Right. And there are so many different audiences alive and you know, in, in the digital space today, I went to the restroom earlier and I saw a payphone. I'm like, there's still payphones around here.
Yeah. I remember having to use a payphone in high school. But I have a question for you.
Yes. What's like one thing that you would change with either like awareness or marketing in like cyberspace that you like, wish it was like already fixed? I think that it needs to be, to your point, it needs to be explained in a way that this is achievable.
Right. And it's not scary. It's not scary.
It's a massive opportunity. It's only growing. Mm-hmm.
So the opportunities will only grow. Yeah. But I think to your point, from an education and awareness perspective, I I I hundred percent on that consistency, but it has to be explained clearly.
Yeah. A lot of people like to get on soapboxes and all these acronyms here, there Oh, We don't talk about acronyms. No, I do not say pushing.
Yeah. I don't even say pushing anymore. They're scam messages.
Yeah. Yeah. That's what it is.
Yeah. No one, if you start doing like technical jargon, their eyes glaze over Yes. And they're gonna be like, I know.
I can't even touch that. Yes. That's not even something I wanna touch.
I've learned that from my radio role where we talk to more consumers. Mm-hmm. It's, it's how do you take com and you and I were both in the sciences, both in aerospace back in the day.
Right. And it's about taking complex topics Right. And converting them to digestible sound bites that a non-technical person can understand and go, I get it.
Yeah. Well, I don't feel like I ever was supposed to be in cyber in like a weird way because I never wanted to be. And then I learned everything on the job and I still, I don't know if about you, but I still feel like I never know enough.
Oh yeah. Which is the best place to be by the way. Like, I always wanna, I wanna be in a room that everyone knows something and I know nothing.
Yeah. First of all. But then I also just feel like because of that, I like had to learn weird ways.
Like I don't think I'm, like, my brain is supposed to operate the way that most cybersecurity are, and so I have to learn it in a different way. That's pretty Well it's Not Diversity. Yeah, it is.
But which Is so necessary. Yeah. You brought up earlier, you know, when you started your influence career and that you couldn't, there was that saying like, we can't be what we can't see.
Right. I do a lot of women in tech events. Yeah.
And it's true. Yeah. We need to have mentors out there and sponsors Yeah.
That look like us, that feel like us that go, okay, I could be accepted here. Yeah. And the older you get, the less you care about that stuff.
I will tell you. Yeah. But, um, Yeah, but it's the younger generation that we're trying to get in.
Yes. You know, It's Yes. But there's so much job opportunity.
I mean, like, I I work with companies all the time that will have like different, um, programs. Yeah. Like some like Boomie, I'm Mc Boomie World in a couple weeks and they have, um, a veterans program.
So they work really hard with, with war veterans to get them into cyber and into technology. Right. And I, I think there needs to be more light shined on things like that.
Like there's a lot of doors and pathways, but to your point, if the employers are making it complicated Yeah. That's not gonna help that pathway become any Easier. And the other thing is, I don't know about you, I feel like as a woman, because there was like DNI DNI initiatives when I like got in like 12 years ago, I always felt like I wa I didn't know if I was hired for the right reasons.
Yeah. Even though, like I, and I, I'm not, I'm gonna toot my own heart. I had an incredible resume.
Like, I, I had three jobs in school, I had three different internships. Like I nailed my interview, but I always had that like, weird thing in the pit of my stomach being like, was I only here for, because I'm a woman? Did I check a Box?
Did I check a box? And then it really made me like the imposter syndrome actually really like set in a lot of times. Yeah.
And I, I actually am kind of happy, like I want as many women in this field as possible. Yeah. But I also want the best, most qualified people in the role.
Yes. And so I want to make sure, I feel like it helps with imposter syndrome too, from a woman perspective. I agree.
Like, don't hire a woman because we're a woman, hire the person for the right role. Yes. And we're, we're trying to train the women to be the right woman.
Yes. Right. So I think there's like a weird, well There's also all these stats and I'm forgetting the actual specific stats, but like, like, I don't know, 80 plus percent of females if they see a job on LinkedIn, don't, and they don't meet, they don't apply every requirement.
They don't apply. Whereas men Oh, I got that. Yeah.
And so, and now with ai it's even more challenging because everybody wants people with AI experience. You're using AI to write your copy. How do I set out?
I Use it, write everything. Oh, I wrote my radio, we hit for it tomorrow morning. Right.
GR chat this morning. Yeah. It's the best.
It is the best. I, I like it as a, a creative inspiration. That's how I leverage it.
I, I have a lot of good stuff going in my mind, probably you can tell with all the conversations that we have, but it, it really helps me do like a brain dump and then it helps me reorganize, like Oh yeah. How I should frame things. Yes.
So that's what I love about it. Yeah. But I think for folks that rely on it, that's a different story.
Yeah. And I think I, I was reporting on this recently about like, it's a really high percentage of, of students between like 17 and 25 who are dependent on things like chat, GPT. Can You imagine going through school with that as a resource?
I would dumb my thesis would've dumb would been so much easier. Yeah. Or I would be, that's, that's a challenge.
Are you not learning enough or retaining it because you can get it spit out you back at you in seconds. Yeah. So it's, it's a double-edged sword.
Yeah. But it's like, like I say, technology is inherently neutral. It's used for good and bad.
Right. Let's find all of the good uses and amplify that everywhere. For sure.
I feel like a sense of responsibility as, as, as a tech executive and now a reporter and media person to help more people understand how not to be afraid of things like ai. I talk about it all the time on the radio. Yeah.
Why there are risks and I want to help you be aware of them, but let me tell you all the things that it's already doing that you're interacting with that you don't know. Well, And I think I, I was talking to someone else about this, like, I feel like everyone's like, oh, buzzword ai. Buzzword ai.
But like, we need to move past the point of like, ai, because ai, even when AI was a buzzword like two years ago Yeah. It was already implemented. People just didn't talk about it.
Exactly. So I'm like, it's already like, I mean, net, the Netflix recommendations, your Instagram, the face filters. Yep.
Your Instagram recommendation, everything. Oh, it's already nice. Already use technically ai depending on your definition.
And so it's like, okay, well how do we move past to like, okay, AI is like everywhere it's gonna take over. Here are all the, the scary risks to, okay, let's implement this in our day because we're not gonna run from this. We can't, we can't.
It's already here. Oh yeah. So how do we like optimize it the most?
I think I made a video about like the four things you shouldn't be putting in like ai Yes, I saw that. I saw that. I'm like, we're gonna use it.
So like, here's just FYI don't, don't be putting this information. Little guardrails. Yeah.
But, but then there's healthy yeasts of it and it's like what? Like some of the applications in healthcare Yeah. Are phenomenal.
Yeah. Detecting skin cancer, I mean, you name it. And, and the trainers left the station.
Right. Chat. GPT was born.
It just catalyzed this movement. Yeah. Yeah.
Where every company that I work with, either, either as a marketer or as a member of the media, we have to have an AI story. Well, what is it? Yeah.
It has to be real. Yeah. And then you have to go, okay, here we are, RSA, how do we secure ai?
Right. It can be done. It's not easy, but it can be done.
We can get proactive against the defenders. Yep. We just have to be constantly doing it and learning and evolving.
Yep. And the tech is evolving faster than laws and regulations. It's just such an interesting time to be alive and be working.
I know. I'm, I'm, I'm, I'm trying to figure out how the, to best optimize it, honestly. Yes.
Like how, what do I do to like, make sure that I'm fully taking advantage of this, like massive growth. Agree so Fast. Agree.
It is so fast. What's next for you? We know we follow you on at cybersecurity.
Girl, you were just in Montega. Was that the NATO youth summit? Yeah.
Awesome. Yeah. And then you came here, got stuck in Barcelona, but you came here Barcelona, but I came here.
What's Next? What can we expect to learn from you next? I mean, I'm gonna just constantly, constantly be throwing out amazing videos hopefully and educational videos.
Yeah. And I'll tell you my like, future goal is to like have like a kids, like Bill and I kind of show, but for like STEM and tech and ai. Love that because I, I am, and something I talked about at NATO was like, we have so much responsibility and opportunities with these kids to make AI and cybersecurity not a scary thing and not a necessity, but like fun.
Yes. And if they're able to be like curious and play with it from the beginning, we are gonna see massive growth in that field from when they as, as they get older. Um, and so I'm like really excited about the future of that.
But I would love, I wanna do like a TV show. I, I'm ultimately just trying to build like a trustworthy, continue to build a trustworthy brand. Yeah.
Because I do feel like it's my responsibility to, to be the one person that's like, Hey, no clickbait, no bs. Here's what's going on. Yeah.
And here's what you need to do. And like, have, have fun. So, Well you're democratizing access to all of the generations for cybersecurity.
Why it should be part of their, their fabric, their personal fabric, their professional fabric. Yeah. And why it's a good thing and not you're demystifying it.
Yeah. And that's needed. Yeah.
That's what I always say. I always say like, I'm demystifying cybersecurity as a whole. Like in general you are careers, cyber, whatever it is.
Just, that's where I wanna be. Well keep doing what you're doing. I learn intent from you like every day.
I appreciate you responding to my DM the other day. I'm like, Kaylyn responded. I felt like So cool.
Oh my gosh. I appreciate you messaging me. Of Course.
Yeah. And I wanted our audience to be able to learn from you because this is something that is just the fabric of our daily lives. Yeah.
And we appreciate your insights, your time, and sharing all of your knowledge with us so consistently. Thank you Caitlyn. Thanks so much for having me.
It was my pleasure. For Caitlyn, Sarah, and I'm Lisa Martin. This wraps up four days of coverage at RSAC 2025.
Yay. Big hand of applause for our amazing production crew with text on tv. We thank you for watching.
You can find all of this content by next week on the socials. And if there's anything that you wanna watch again, lucky enough, you can do it. tv.
com. Too many, too many brands to mention. But thank you for giving us your time.
We hope you've learned from our guests. We'll see you at the next show. Hello and welcome to the AI Leadership Insight series.
I'm Amanda Ani, and with me today I have David Caruso. He is the Vice President of Financial Crime Compliance at Work Fusion. How are you doing?
I'm doing good, Amanda. Thanks for having me. Thank you for coming on the show.
Can you share a little bit about Work Fusion and what services do you provide? Sure. So Work Fusion is an AI agent company and we focus solely in one space, which is financial crime compliance.
Uh, so we have agents that help financial institutions of all types and sizes from the US and around the world, uh, execute a lot of the daily tasks that are required in order for them to comply with all the various laws and regulations that they have to comply with. Just one example, uh, that's been in the news a lot over the last few years. Whenever you, uh, read about the US government sanctioning to a Russian oligarch or, uh, anyone like that, financial institutions have to search all of their records and determine whether or not they bank those people.
Well, that can be very onerous, very manual in nature. W among what we do is we provide AI agents that perform those tasks and do that work that allows banks to comply with those, uh, US and other, uh, rules and regulations very quickly, very efficiently, and, uh, yet, you know, much less cost. Okay.
Yeah. That's a, a big challenge, I imagine. So our topic for today is artificial intelligence and how it can be used in financial crime prevention, anti anti-money laundering and compliance.
So from your experience, let's first talk about what are some of the biggest issues and concerns, um, when it comes to money laundering and compliance? Okay. Well, the one issue that has existed since any of these rules and regulations went in place, and some of them are 50 years ago, is every year there's more money laundering and there's more fraud.
So it just, this sort of, the nature of human beings, there's a lot of opportunity, there's a lot of money, there's a lot of crime. And unfortunately, all of that at some point involves financial institutions and mysa financial institutions. You can think of banks that we know, but also a lot of new company payment companies, a lot of FinTech companies.
So it's sort of anything that moves money, uh, or has a customer is, is prone to this. So with this increase in crime that unfortunately continues, uh, there's a great need for a lot of people to help financial institutions either prevent this ideally, or if they can't prevent these types of customers and activity, they have to detect it and report it, uh, by law. And so traditionally that's meant that year over year financial institutions have to hire more people, invest in more systems, and AI is impacting that because AI is now able to do much or i I say, significant amount of, uh, the work that's involved in detecting, investigating and reporting, you know, this activity.
And I'm happy to talk more about that, uh, or, you know, take it any direction you'd like to go. Yeah, absolutely. I'd love to hear some actual, um, use cases for AI in assisting.
Okay, sure. Like I, I mentioned at the top of our conversation, uh, there's a lot of work that's involved in what we, in the industry call screening. Uh, maybe many listeners are also familiar with the concept known as KYC or know your customer.
That's a concept that seems to have made it into just the general average citizen discussion these days. And so in those, those areas of screening, uh, a lot of this work, and you can imagine, I just think about how many people there are on the planet, how many people want banking relationships or financial relationships. When those customers, uh, sign up for accounts they have to go through, you know, what's called an onboarding process.
Well, AI agents can accelerate that. They, they automate much of it. Let's just take for an example, uh, where a customer might snap a photo of a passport or a driver's license.
Well, AI can extract all the information on that, right? It can, it can read the license, it can read the passport, it can identify things like dates of birth, addresses, uh, names. And so what a agents can do is they obviously can do that much better, much, much faster than a person can.
And so that's just one element of, of knowing the customer. Uh, other, other use cases involve actually detecting potentially suspicious transactions. So let's say that they, they are a customer of the bank.
They've gotten through the KYC system, but they're actually, maybe they're who they say they are, but who they are is actually a bad person. The bank just doesn't know that yet. So they begin to engage in activity that can be suspicious.
For example, a lot of cash activity or maybe wire tra uh, unusual amounts of wire transfer activity to all different parts of the world that, uh, in those parts of the world might be associated or have a, you know, a history of being associated with corruption and crime. Uh, so there are analog systems that detect that. But the problem is those analog systems, and what I mean by that is technology that's 10, 15, 20 years old, they detect a lot of that activity.
But unfortunately, much of that activity isn't actually suspicious. It's, it's, it's acceptable. It's, it's nons suspicious, but banks have to hire, you know, collectively, hundreds of thousands of people are working on matters today, sorting through this, uh, these transactions and AI can just sort through those transactions, can spot patterns faster, can expand the networks of people that might be involved in that activity, uh, at a rate that human beings just simply can't.
So, you know, it it, it, it's better at detecting, uh, now what's interesting is a lot of this detection is what we in the industry call level one. So a lot of it's that sort sorting through, it's finding the things that might require more, more time, uh, more experienced people to look at. So what we're doing is we're presenting those matters to the person, the, the trained investigator or analyst, uh, faster.
And in some cases, a lot of the rudimentary document and information gathering that they would spend unfortunately hours doing well now that's in front of them so they can spend time, you know, making decisions, rendering judgment, uh, and hopefully stopping the growth of crime. So what would be considered level two or three? And does AI have a, a use in those levels?
Yeah, absolutely. Uh, and I, I've been in this field for about 30 years, financial crime compliance, but not all of it in technology. Much of it on the operations side, doing the type of work that I'm describing to you.
And just as we see AI improving in every aspect of ai, whether we'll just use it for our own purposes, uh, just to, you know, plan a vacation or, or, or whatever it is. So, so that same sort of improvement we're, we're seeing similarly in our space. So to answer your question, yes, that level two work, that requires more decision making, that more of that can be done as well.
Uh, so yes, because like most things, uh, well, like many things, ultimately what we're looking for in our field is patterns, is, you know, are, are, is this activity indicative of a pattern that we know to be likely to be money laundering or fraud? And so the AI can surface those patterns, which is again, be more level two type work. Uh, and yes, you can have, you know, large language models can now draft reports.
You know, as you might imagine, there's a lot when you're reporting activity to the government, there's a lot of requirements around what you have to write, how you have to tell a story. And so yes, there, there's, there's that sort of level two capability is, uh, you know, so it's here already. Uh, and I would say if we had, if we spoke next year at this time, it, the rate of of improvement would be significant.
It's interesting as we talk about using AI to solve these issues, I would imagine on the flip side of that, that a lot of these threat actors are using ai, um, and making all these crimes a lot easier on their end as well. Yes. And, and one of the ways in which they do it is they create what sometimes is referred to in the industry as Frankenstein ID IDs.
So in other words, they, they don't create entirely fictitious people or companies. They'll actually take stolen information or, or misappropriate information about a person or a business entity. So it's, it's true ish.
'cause there's some things in there that can be validated, but then there's other information that isn't, it's synthetic, it's, it's created. Um, and that's able to get past a lot of sort of that onboarding review and, and screening. So, 'cause re remember the how money is moved, that that hasn't changed that much over the years.
Now it can be moved much faster, you know, almost instantaneously now, whereas in years past, it might take anywhere from three to five to 10 days for financial transactions to be settled. So they are taking advantage of this almost instantaneous settlement, but ultimately what they want is they want that instantaneous settlement, but they also wanna mask who they really are. So you, you're sort, you're, they're, so, yes, there's, uh, and you know, as consumers, as honest law abiding consumers like you and I are, Amanda, we, we want instantaneous transactions, right?
When I send my children money, they want it now. So, so the things that we're demanding as consumers, yes. The, the, the bad guys can, can avail themselves of those same conveniences.
So some of it isn't necessarily, they're creating new means and methods to, to commit fraud or launder money. They're just riding along the same rails we are. So, and of course, financial institutions have to constantly balance the desire to give those features to customers who want them, along with the risks that those features, uh, will create.
From your experience, what are some of the challenges that financial institutions face when they're implementing AI technologies? Uh, well, I think one of the challenges is simply that, and it's sort of a, a contradiction where, what I'm about to say is, is that the reason that financial institutions do this is the, the by law they have to do it. So it's, it's a highly regulated environment that in however, that, that regulation also slows things down.
So, on one hand you have regulators saying, banks, you have to keep pace with this. You have to modernize. And if that involves adopting ai, so be it.
But in, before you adopt ai, you have to have very, uh, well-defined, uh, strategies for how you will do that. You have to put in a lot of governance above it. So in a way, you have the, on the one hand saying, get at it, put in new technologies, and on the other hand is, but don't do it so fast that you do it poorly or actually increase the risk.
So there, there is some, you know, that again, that's existed forever in the regulated, regulated world. Uh, but I would say it's probably a little more heightened now, uh, because there's, everyone sees the rate of improvement with AI and realize that, that we have to adopt this. So how do we do it, uh, wisely and safely without falling behind, you know, our peers and, and what the regulators expect from us.
Yeah, absolutely. Well, AI is advancing quite rapidly. So what do you envision as the future of AI in regard to financial institutions and crime prevention?
Well, as far as financial institutions writ large, that, that's a whole nother multi-hour conversation. Uh, because, you know, there's a lot of just how, how our banks and financial institutions operate. You know, many of them still operate on very outdated, antiquated systems.
So, um, the financial crime professionals within financial institutions don't, don't typically drive that modernization. So, but, but, so they'll have to follow that. But, but separately, um, yeah, there, there are sort of obviously the, the, the agent AI technologies can be adopted.
Uh, I do think it's gonna change a little bit. You know, A A ML compliance is about 20, 25 years old. There's been a lot of ways in which those operations have been developed and staffed, uh, over those 25 years.
I think AI is going to force a lot of executives and management in the space to rethink how they're staffed, uh, the, the, the, the specific skill sets that are needed. So, you know, there, there's a lot of change coming. Some of it from AI itself, and then much of it from the second and third order impacts from ai.
Alright. Well, if there was one key takeaway you could leave our audience with today, what would that be? Uh, that there's been, for the last five to 10 years, there's been a lot of discussion about what will happen, you know, what how, how what will happen when we see the technology, the technological change, uh, that a lot of people talk about.
Well, that change is here now. And, you know, for someone who's been in the industry as long as I have and has heard about this for as long as I have, there does remain probably some level of cynic ci cynicism or skepticism. But that's should be in the past.
I mean, this, the things I've talked about today are happening today and financial institutions all over the world, they are deploying ai, uh, you know, all the components of ai, machine learning, natural language processing. So the takeaway should be, uh, if you're in this space and you're not availing yourself, uh, of ai, then you are going to be falling behind your peers. And when you operate in a regulated environment, falling behind your peers is, is, is a bad place to be.
All right. Well, thank you so much for coming on the show and sharing your insights with us today. Thank you, Amanda.
All right. And thank you to our audience. Stay tuned.
There's more. Welcome back to Tech Techstrong TV guys and Lisa Martin. Great to be with you.
We are live at RSAC in San Francisco at Moscone West, having great conversations with leading cybersecurity experts across industries. For the next four days of live coverage, Alan Shimmel and Mitch Ashley will join me in the next couple of days. So be sure to keep tuning in.
My next guest is Chris Weal, chief Security evangelist at Veracode. Chris, great to have you on Touchstone. Hi.
It's great to be here. You are an OG cybersecurity expert. You've been in cybersecurity space for probably you, you said you've been to like at least 20 Rs a's Right.
Talk to me about the evolution you've seen, because as technology advances, the good guys have access to it, the bad actors have access to it. We've got, we're in this AI era now, which just spreads that attack surface even more amorphously. Absolutely.
What have you seen that struck you over the last 20 years? Well, I mean, I think we keep making the problem harder and harder for ourselves, uh, because we keep making more software. We keep expanding our attack surface.
Someone was telling me today that, um, there's risky plugins for teams Now. I'm like, really? There's plugins for teams.
So like, there's just more and more software coming at us constantly being deployed, and all of that software has risk. Yeah. And now we have AI generating code Yes.
Which means more software faster. Yes. Um, so I, you know, that's, that's what we have to do as a cybersecurity industry, is protect this evolving attack surface.
Yeah. Which the technology changes. And, you know, the developers build new stuff.
They change technology's on us, and I always feel like security's always catching up. Okay. But I do think we're making good progress.
Yeah. Good. When I, when I, when I spoke earlier today, my talk was secure by design.
Are we winning? Yeah. And what I wanted to show was there are some, there is some good news, there are some good indicators.
And we derive this data from Veracode's customers, we call the state of software security report. Yep. And in that data, it actually shows that over the last 15 years, there's less vulnerabilities in the software that vendors are producing.
That's good. And it actually was slow, very slow incremental progress for the first 10 years of the report. One, 1% a year improvements in apps that didn't have one of these au top 10 vulnerabilities in them.
Okay. But in the last five years, we had 4% a year improvement. So we went What Account for that acceleration?
Yeah. Well, that's what I want to figure out. Right.
Okay. Right. Right.
I mean, it's, it's great to see the outcome. Yeah. And then you try to figure out like what are the practices people are doing?
What are the motivations that is causing them to make better software? Right. And then, you know, I would say like, let's have more companies do that.
Do you think that's a DevSecOps Absolutely. Evolution. Absolutely.
And developers and security folks finally coming together to collaborate A Absolutely. I think the DevSecOps process gets that security more closely embedded into the actual Yeah. Development workflow and the whole shift left.
Yeah. And it's not the only answer, but it is definitely one of the things that you need to do to make improvements. And that has been a process change that's really taken hold in the last five years.
Oh, yeah. Well, it's cultural too. Right?
So I think that is one of them. Yeah. Developers are, are very aware of the security tools that are running now, where 10, 15 years ago it was something that someone else did.
And, you know, they, they pressured me to maybe fix a few flaws and I didn't really understand it. Now with DevSecOps, the improvement is, it's part of their job and, you know, we're, we're getting there. It isn't absolutely part of every developer's job.
Sure. But, um, I like to say it's part of the definition of done software is Yeah. The features are in there, they've been tested and they work and it's been security tested and the security bugs fixed.
Yes. Now it's done. And so that process improvement is what's making one of the big improvements in, in this outcome.
That's good. It's, I'm sure you were pleasantly surprised to see that increase after 10 years of, of very small incremental Right. Improvements if you Jump percent a year.
I was like, and we were starting at, uh, I think it was 23% passing rate and we got to 32% after 10 years. I was like, I'm gonna be long retired. Yeah.
Before we get to over 50%. Yeah. But then we had this acceleration in the last five years, and I feel like we can actually improve things a lot over the next five.
Yeah. Well, the, the challenge, it's kind of like a, it's a flywheel, right? I mean, we're, you talked about we have so much more software now.
Right? But that phenomenon is only accelerating. Absolutely.
It's not gonna slow down. So how does Veracode help get control for the developers? So from a business perspective, nobody wants to be the next headline.
Right. Is it possible to gain control over this? Yeah.
So yes. But it isn't something that happens overnight. And one of the big reasons is when you first test your software, you have years and years of security debt, all that time.
You weren't testing the software. You had vulnerabilities that you were completely ignoring. You didn't even know they existed.
Right. And then you, you sort of have to slowly drive down that security debt. You have to take, allocate a percentage of time.
'cause you can't do it all at once. You can't, like, um, I know Microsoft said they did this back in like 2003 with their trustworthy computing memo. Bill.
Bill Gates said, we're gonna stop writing software. Everyone's gonna learn how to write secure software. We're gonna fix all the bugs.
Mm. It's like, you can't stop your company for a year, let alone a month. Right.
You have to weave it in. Yeah. And you have to, you have to have to slowly drive, drive that debt down.
So that's what we do when we start engaging with a customer, is we put these tools in place, but we say you can't, you still have to keep shipping your software. Yeah. And unfortunately, you're gonna be shipping software, whether it's to the cloud or to your mobile device or to your customers on-prem that has that has security bugs in it.
Yeah. 'cause you can't fix them all right away. Right.
Right. But the, the, what you wanna get to is have enough capacity to fix at least the bugs that you're, the new bugs you're creating. So you sort of stop the bleeding and you're not getting worse.
Yeah. And then you incrementally make, make pro process. So it, it typically takes a company a few years Okay.
To go from no process to being best in class. Okay. I would say like four or five years.
Oh, okay. So that's a journey. Yeah.
It's A journey. As the, the evangelist. Where are you having conversations within customers?
Is it at the CSO level? Is it at the ELT level? Is it the developers?
All the above. It's mostly with the developers. Okay.
Um, and that's great because like all the security people already know who I am. They know who Veracode is. They know what we do.
Um, but the developers have no idea. Right. So like a company will have a developer day where they'll fly all their developers to one location and they'll have talks throughout the day.
I love speaking at those talks. 'cause I get to engage directly with, it might not be the developers, it might be sort of the development managers. Okay.
But it would be developers and architects too. But that's your audience. And that would, that would be the audience that I really like to like, to talk to Talk a little bit about.
You mentioned the Secure by Design campaigns a launched that what, a couple of years ago? Yes. It's been a couple years now.
Yeah. It's been a couple years. They launched their, uh, secure by Design Pledge Two years ago.
What's the, what's the conceptually So Secure, philosophical. The by design has been around for a long time in, in my talk. Um, and my co-presenter, actually Jason Healy, he's from Columbia.
He's a security researcher. He talks about, uh, a paper written by the Air Force in 1972 that actually said, we have no hope to build secure software unless we start from the beginning and build it secure by design. Oh, okay.
So the concept isn't new. Got it. It's just that people haven't been practicing it.
Why Do you think that is? Is it behavioral? Because when you start building software, that's the time where time is the most precious.
Mm-hmm. Right. You're like trying to see if you can get the software to market.
Yeah. It might be a competitive situation where you're doing catch up with your competitor. I mean, the competitive pressures is the big reason Sure.
That people aren't fixing flaws 'cause they need that feature. Right. Or they have a customer complaining about something.
So when you have those scenarios, the fixing a security bug becomes deprioritized. Right. And I, and I think the Secure by Design is deprioritized because it's in the beginning of when you're building software, but unless you do it, you kind of have no hope over the lifetime of that software of having it be really secure.
Right. It's really hard to bolt stuff back. Right on.
Like, if you look at what Adobe did with Flash, I dunno if you remember, but there was years after years of critical bugs in Adobe Flash. This was really old software. Adobe Flash was created in the late nineties.
Yeah. And it persisted until, I don't know, like 2015 or something like that. And they finally said, we can't keep up with the bugs.
Wow. We're gonna, we're gonna, we're gonna, we're gonna terminate this software. Oh, wow.
And, and we're gonna shut it down and end of life it. Yeah. Um, that's an extreme case.
Yeah. But it, it, it, it sort of shows the point because they didn't build it securely in the beginning and it was very popular, very critical piece of software and all kinds of websites. Yeah.
Um, it was constantly attacked and they could never, couldn't catch up. So that's sort of the worst case scenario. Sure.
Um, but, but that's, that's, that's what can happen if you don't start secure by design. Well, it needs to be baked in from the beginning. Application security.
Where does that belong in production? It can't be a bolt on afterthought because we've companies time and again, have proved that doesn't work. Right.
Like the worst, the worst place to put it. It is like, well maybe just scanning stuff after you put it into production. Yeah.
That would be the worst. But people, most people realize that that is, that gives no time to fix anything that you find. So, uh, a lot of companies scan the code or test the code just before production.
Okay. But the problem is with DevSecOps, with so many quick iterations where you might be pushing code on a daily basis, there's no time to both test it and fix it and fix it. So you gotta, this is where the whole shift left comes in.
Ideally in the cus in the, in the developer's IDE or at pull request time when that code is changing, test it and you have the opportunity to fix it. Yeah. Then, then too.
But I think that that also is a little shortsighted just to shift left, because so we say you have to shift right too. Like you have to understand what's going on in production. Sure.
Because there's stuff in production that doesn't exist on the developer's desktops interacting with the cloud environment that might be configured differently. There might be other software deployed in, in that, in production that it's interacting with. So you need to test there too.
Sure. So we say shift left and right. Okay.
Both as early as you can and in and, and in production to give you that complete continuous Picture. Yeah. And that's one of the things that we're driving to at Veracode.
We have this product called Veracode Risk Manager, which connects results found in production back with the results of your testing. Okay. Back with the code and the root cause of the problem to, to, to make one coherent picture of risk and where to fix it.
The best place to fix issues. So instead of fixing a hundred individual issues, if you can determine it's really just one issue. Yeah.
You wanna do that? Yeah. Go up upstream.
So that, and, and so that's, that's our drive is to constantly make things more efficient for the developers. Yeah. 'cause we know their time is so limited.
Yes. Yes. So we want the context point them Right.
To the fix. And now we're introducing ai, generative AI based fixing. Okay.
So have the AI fix it. Yeah. And if you think about, like we, we talked about velocities are getting quicker and quicker.
Yeah. There's more code. Generative AI is just making that go faster.
Exactly. Right. So I've seen data to say each developer can write 50% more code, um, using generat of ai.
Yeah. So now you have 50% more code per developer who's gonna fix the flaws, Right. 'cause we can't code, we can't just, That's gonna be secure.
So you need to Right. You can't assume that the generat of AI stuff is secure. So we gotta test that just the same.
But then you need something that can fix it. Yeah. And so we are focused on automating the fixing process using jitter AI as much as possible and make things that are reliable and built in that just maybe every time vulnerabilities are found in a pull request, automatically fix them.
Yeah. It sounds like what you're giving the developers is visibility. Yep.
Way more visibility than they had before to really understand where things are, where the vulnerabilities are, how to fix them. Allowing them to, to use gen AI to be more productive. Which is what they want.
They wanna write code EE Exactly. They wanna generate applications. They want a vibe code.
Yeah. They want a vibe code. Yes.
Who wants to look up for what this API's I know are That's so hard. He already knows it. Yeah.
Just say, I wanna make a database call. Yep. Yep.
Yep. What's your favorite customer story of Erica that you think really shines a light on the true value you are delivering so that organizations can really become cyber resilient? Yep.
That's a journey in and of itself. Yeah. So I, I think the way I like to look at it is, if we look at our state of software security report, which we came out in 2025, um, we, we, we look through the data and we have, you know, we have a lot of averages.
The average application, the average bug takes this long to fix. The average application has this many percent of O os top 10. But then we split it into quartiles and we said, what are the organizations that are leading, what are the ones that are doing the best?
Yeah. And so it, it shows you what you as a organization, you can benchmark yourself against this data and say, I, I want to improve. I want to be like that.
So that's, that's sort of the story I like to tell is, you know, the, the best organizations are fixing 10% of all the security bugs they know about Okay. On a monthly basis. And Is that acceptable?
10%? Yes. That will keep you your head above water.
Got it. That'll keep your head, that'll keep your head above water. Um, so, so we look at those metrics of the leading organizations, like how fast are they fixing flaws?
Is it taking them six months a year, or is it taking them 30 days? And then it shows you like, well it's, this is possible. Yeah.
This is possible to do. Yeah. I would love to add in survey data Yeah.
To say like, exactly how are you getting to these outcomes? Sure. Because we just see the outcome in the data.
Okay. We don't know what they're actually doing. Right.
That would be nice insight to have. Yeah. So I, I would love, love to do that to tell a better story.
So a a a customer or just any company can, can look at our, our report and say, if I do these things, I'm gonna get an outcome like this. Right. And I don't have to just like, listen to something as a best practice.
This is what companies that are getting these good results are actually cheating, are actually doing. And I think that's con connecting practices with outcomes Absolutely. Is super important.
'cause we, everyone here speaking in all these halls is talking about what's the best way to do this? What's the best way that, but they have to show that the actual outcomes are of real world companies. Yes.
Or it's just a pipe dream. It's all about outcomes. Yes.
Last question for you as we're living in this AI era, you know, it's funny, AI's been around for decades, but chat GPT was born and then everybody is talking about ai. It's, there's a lot of AI washing going on. You can't go to a conference without hearing tons about ai.
But how in this AI era, you know, organizations, I talk to CMOs a lot, or everybody's embracing gen ai, agentic ai. How do you help organizations defend this digital frontier, the age of ai when the frontier is continuingly changing? Right.
One of the challenges is just knowing where the AI is. Yeah. Right?
Like a lot of it is like it's creeping into all these different products. And like sometimes CISOs are completely surprised that something has been transcribing all of their employee video conferencing calls. Yep.
Right. Oh. 'cause anybody can shadow it.
Anybody can. Yeah. You can just use order or zoom every, everything's got note takers.
It's totally, so it's again, this AI attack surface Yeah. Is percolating through, through everything. And, and if say you're using a SaaS service and you're sending your data out of your enterprise somewhere else to be processed, right.
Are are they training on my data? Mm-hmm. Right.
Is there a chance that my, my, my secrets end up in, in the answer to someone else's support question. Yeah. Yeah.
Right. So that's, those are the things you need to ask or CISOs need to ask Yeah. Is where is all this AI Yeah.
Activity happening? Because a, all AI has to learn from something, right? And there's so much value in AI learning from proprietary data sets.
'cause everyone can train on the o open source code Yeah. Or all the, you know, published books out there. There's a lot of stuff they're not supposed to be training on, but Sure they are.
But they are because it's a, because it's available. Right. But if you have a proprietary data set you, that gives you a competitive advantage.
Okay. And what's a great one? Like the data my, my customers are creating, right?
So this is, this is one big thing that people need to be aware of. The other one is, where is AI being built into my own software? Right.
Like, if I'm building a chat bot for my website is, is they hooking in chat G-P-T-A-P-I into that thing and they're having it, it, it, it talked, you know, that's a risk. Now I can have things like prompt injection. Right.
Maybe attackers can get into my proprietary data through the chat bot Yeah. My website. 'cause it has access to my customer records or something like that.
So there's a risk of losing your proprietary data and there's a risk of, um, you know, by people training on it. But there's also this risk of attackers Yeah. Using the AI you're building in to steal your data.
Wow. So it's, it's a new it. I I feel like it's the cloud era all over again.
Okay. Where cloud changed everything. Sure.
I think AI is changing everything again. Yeah. What's the one positive that you can share with the audience that, that you've seen from this evolution that we talked about at the beginning of cybersecurity?
What's that golden nugget? We're going in the right direction here. I think we are going in the right direction.
Um, and, and, and the, so the big picture is like, as this technology constantly changes, is it helping defenders more or is it helping offense Right. More. Yeah.
Right. And we have to constantly think like, how does, how, how, how does defense constantly, constantly get better? Right.
And one of those things is, is secure by design. Yeah. Right?
That is, that is something that, that helps the defense get better because you have more defendable software, less vulnerabilities, less patching, less incidents to respond to. Right. So, um, I, I think the, the secure by design is definitely the biggest thing that I'm seeing as a, as a, as a, as a potential game changer.
Excellent. Um, but I also think that this connecting the dots of, um, the technology with the root cause of the problems. Yeah.
So this attack surface management discovering vulnerabilities, but then connecting it back to the root, the root problem. This is giving us much better visibility. Exactly.
I was just Yes. In into risk. So the visibility into risk is, is getting, getting better, better getting, but we have to act on it.
Yeah. Right. Like that's, that's that, that's, that's a Yeah.
But then you have to make improvements based on the information you have. Can't just get this discre information, then do nothing with it. Right.
It's a never ending story. Yeah. Chris, thank you so much for joining me on Techstrong TV today.
I learned so much from you. What you're doing at Veracode, what you're enabling developers to achieve. That visibility, those blinders are coming off and that's so important as cybersecurity will just continue to evolve in good ways and not so good ways.
Gotta stay a step ahead. We appreciate your insights. Thank you for joining me.
Thank you so much for having Me. Oh, my pleasure. For Chris Weis Sopel, I'm Lisa Martin.
You're watching Techstrong tv live from RSAC. This is day one of four days of coverage from techron. Keep it on this channel.
We've got more great content coming up. Thanks for watching. Hi everybody.
Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer here at Techstrong, and I'm here with my co-host Tracy Reagan, creator and CEO of Deploy Hub and very active member of the Linux Foundation. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Techstrong.
We, we recently launched another new site, Textron It. So go out there and check it out. Lots of great content, um, fun stuff to watch.
com and see what's going on and what you might wanna jump in and submit papers to participate in. 'cause we would love to have you, and you should always tune in to Textron TV every day to watch all of our great shows and interviews. Hey, Tracy, what's on your mind today?
So in our last call I talked about, I believe it was our last call, um mm-hmm. Renee James, uh, who, uh, started a company and sold it for six and a half billion dollars to SoftBank focused on, um, chip design. So I'm gonna follow up with that.
And this is a little more sober, um, but we as a country are facing a very uncomfortable situation, let's just put it that way. Um, we're watching now, uh, China, um, do, uh, warfare practice in the China Sea. And what is that about?
It probably is about a blockade against Taiwan. Intel is the only US manufacturer of chips, the only one doing it, and they're in a pretty bad situation financially as a company if Intel crumbles, so does the security of the us. It's just the fact, um, unfortunately in Intel doesn't manufacture all the chips that we need.
The chips that we use in military are not manufactured by Intel because that technology is pretty much with, um, other, other chip manufacturers that are making the chips with the expertise to make the chips in Taiwan. So this is a bad situation. We wanna make sure that ti that, you know, Taiwan is not something we have to rely on for chip manufacturing.
Um, so, you know, I I'm not a, I I don't make, you know, investment recommendations at all. And it may not be a moneymaking one. However, right now is a good time to vote with an investment in, uh, Intel.
Um, another thing that's happening around this space is the new administration may get rid of the CHIPS Act and that would've helped, uh, Intel build chip manufacturing in places like Texas, which they have pulled out of for now. So we're in a bad situation, uh, Intels in a bad situation and I'm calling everybody, uh, calling on everybody to really consider getting the intel, um, stocks to go up so that they stay viable as a company making chips in the us. Uh, because without them we have no chip manufacturing and that is devastating.
Yikes. Yeah, that's kind of sobering, isn't it? But it is the reality.
So we wanna talk about it. We gotta keep talking about what's going on and, uh, respond accordingly. Thanks Trace.
Alright, so we have an amazing guest today. We're very excited. And I did not ask her how to properly pronounce her name, so I'll probably had, but I'd like to introduce Sylvia.
Is it Lavin? Lavin? Yeah.
You have it. Killed it. Woohoo.
I know French and my ex-husband's family is all Italian, so I had enough of that stuff in my brain, so Wow. I'm pretty proud of myself actually. Yeah, Lavin is a French name actually, so, yeah.
Very. Yeah, that's why I ringed it. I thought it was French all.
Yay. Alright, well, Sylvia, we're excited to have you here today. Tell us a little bit about yourself.
Yeah, thank you so much, Jody and Tracy for having me. It's incredible to be here. Um, so back background today where I'm at is I am the Chief Marketing Officer of Kanji and Kanji.
We work at Apple Devices, so we do device management, endpoint detection, response, vulnerability management, essentially anything IT security needs. You know, teams need to make sure that employees have an incredible, but also a very secure experience working on their Apple devices. And I have a, I have a whole crazy backstory of how I got here, which we can get go as deep into as you would like, but I'll give you kind of the highlights.
So I actually grew up in Africa my entire life. My parents worked in nonprofit. My dad was a pilot in the middle of nowhere in Africa, in a country of Mozambique.
And so I lived there my whole life, uh, came to the US when I was 17 for college. Went to LA and went to college there. Ended up really falling into tech.
I got recruited into a tech company as their first marketing hire. I think I was 22 or 23, and certainly underqualified for that role at the time. Um, and they actually, when they hired me, they told me you're, they alluded to the fact that I was the, the least experienced and, and likely youngest candidate that they were speaking to.
Um, but they hired me anyway. And that was such a launching pad for me. 6 billion.
They're eyeing and IPO they're doing great. Um, so I, I kind of started my career in tech there, um, and really just learned the ropes in the field. Had some incredible mentors who helped me along the way.
Um, and then after that went to a company called DataFox. They got acquired by Oracle. Um, it was actually Oracle's AI group.
This was back before AI was cool. And then, uh, after that I went to, I went to Kanji. So I really love this, this role I, of playing this first marketing hire.
I was the first marketing hire at Kanji as well. I was actually our fourth employee. Um, we're at almost 300 now, so we've come a long way since then.
Um, but I've been here for a few years. Um, and I'm actually based in Miami now. I've been here for three years.
And, um, building a team here and, and growing, uh, the Miami Tech community as well is something I'm really passionate about. Um, but yeah, lots of learnings and, uh, mentors that have helped me along the way on that, on that journey, but excited to be here and to be able to really speak to other women as well that are, you know, eyeing leadership roles or wanting to advance in their careers, or wanting to just find that next level of what does something that's, you know, work that feels really purposeful and aligned. Like what does that look like, uh, and feel like, uh, especially in a leadership role.
So few things I'm really passionate about. We can go, we can go deeper into any of those things that, that you both would like. Well, I'll see what Tracy wants to grab first.
I love your website. Wow. I really love your website.
I love the educ, the educational content videos on it. Um, so I want you to teach us a little bit about how to build a beautiful website that is beautiful, that can attract women, but will also attract men. Right?
It's a really nice website. So, you know, everybody out there go look at our website. It is really beautiful.
Of all the places you were gonna go, that that was not what I was Expecting. That wasn't what I would've guessed either. No, I appreciate that.
Um, yeah, I think brand is really, really important to us. And I think a lot of folks think, you know, especially, you know, we, we work a lot with the IT buyer, right? And a lot of folks I think, think that it doesn't care that much about something being an elegant, you know, experience.
But the website is actually a reflection of our product itself. Like that DNA runs really deep and it comes from our founders and a lot of our team come from Apple, right? Like, this is what Apple cares about and this is what we care about.
I think we've kind of inherited that value. Um, and so brand is just, it's something we prioritize. It's something we care about.
And, uh, for the website specifically, um, something, you know, a few kind of like principles that have really guided us that have gotten us there. I think one is just, you know, uh, consistency and it, it sounds really, you know, simple and basic. But we, we developed that brand sort of the look and feel and design of the site, uh, quite some time ago.
But since then, we adhere very, we're very dedicated to making sure everything looks and feels very, very consistent. I think a lot of a really cohesive, elegant, you know, experience that drives a lot of trust, uh, with men or women is based on consistency. Consistency creates trust.
And so that's something that's very, very important to us. We haven't always done, you know, an excellent job of it. I can look at the website and probably see a bunch of examples of things I wish were even more consistent.
But that consistency, I think creates a lot of trust and is really important. And our, you know, our buyers really, really love it. If, if you read through our G two reviews, everyone's like, it's beautiful to use from, you know, the product to the website.
And so it definitely runs throughout the, the entire company and is something we care a lot about. I totally agree with you. The consistency.
If you click on something, you get a 4 0 4 or some weird thing happens, or I don't think people focus enough, and I've noticed you guys have on how it's gonna look on this versus how it's gonna look on my giant screen or how it's gonna look on my iPad. And you pull it up and you're like, I can't do. So I love it.
I think it's, that's super important. I agree with you a hundred percent trace, what were you gonna say? Well, it's hard to follow Apple, um, in terms of their look and feel.
They have a very specific look and feel. You think about the Apple stores, right? And how those Apple stores feel you really are drawn into them.
There's a kind of a, I hate to call it mid-century modern, but there's a modern clean list to it. It's clean, it's clear. And I feel like you've made an attempt here to stay in line with the way Apple presents things.
And that is not an easy task for a small company. I mean, it, it takes money, it takes focus. And sometimes, um, we don't do that as a small company.
And, um, so, you know, was there a discussion internally of how to put money into this? Um, so I, I know you said it because kind of consistent, but how does upper management see that? Because it's not always the case where beauty and elegance is built into a product.
Yeah, absolutely. And very much so, very consistent. So in the early days of Kaji, when I started as an early employee, we, we've worked with a couple different, you know, groups, agencies, et cetera, to sort of define sort of an anchor piece of the brand.
And so the brand on the website that you see right now, a lot of that came out of actually, uh, a video was a motion graphics video we did with an agency. They created that for us. Um, and so you see the, the, a lot of the graphics with the repeating laptops that are in a, in a row, you know, it's like, it's beautiful.
It's Beautiful. Yeah. It speaks to this.
What we do is we, that's exactly what we do. We get these in massive fleets of Apple devices and we get them in line, right? So like, that's what those visuals speak to.
And that video became such an anchor asset that we were able to build out a lot of brand components around it. So I think a lot of times it starts with a single project like that and then evolves into, and is woven into the, the entire brand. And it's best if a project like that is done when it's the, there's a thoughtfulness to why it's done that way, right?
Those repeating laptops are there because of the scale that we are able to manage. And so there's a thoughtfulness to it and there's a why it's not just a beautiful image. It it actually speaks to the functionality and the value that we provide as well.
Well, I think if they would, if we were doing, you know, some kind of a Emmy award for, uh, educational videos, that that would be on the top of my list. You know, I love the beginning of shows. Mm-hmm.
Like, um, uh, severance has an awesome opening, right? Yes. It, it has, it has a, it's very clear as to what the show is gonna be like.
And I always think that they should have like, some kind of a part of the Oscars or something should be those opening sessions because it's like trying to build a small house. It's harder to do that and to convey a message in something that's so concise. But you've done it.
So I, I encourage everybody to check it out, especially if you're in, um, the technical marketing area. It's a, it's a, it's a beautiful example of what can be done really, really well. Yeah.
But I love it. Yeah. And then you mentioned the educational videos.
I think a big focus for us right now is community. And I hear this across, you know, every CMO that I speak to right now, there's a huge focus on brand and community building. And community can mean something different to everyone, right?
But to us it means we have this loyal following of customers. We have all of these folks in the industry that are trying to learn and advance their careers. Like, how can we be this connecting tissue that brings together all of the incredible knowledge that's out there and share that and provide value to the, to the community, and in that way, bring people together.
So it's about us. Yes. 'cause we wanna be a driver and we want to project, you know, all the knowledge we have internally as well, which is all, we have many smart people internally we get to tap into, you know, to be able to share their knowledge.
But beyond that, it's about bringing the entire community together. And so this is something I'm hearing just across the board as a general focus for marketing leaders and something that's really important to us right now as well. Boy, community building is really so key, isn't it?
Because you want your community to be, feel like they're part of the organization. I think that some of the, um, like Fitbit, uh, there, I mean, there are some really good examples of how important community is in building your brand. Um, Absolutely.
And I wouldn't think, you know, you know that a, a company like Kanji would be that focused on building community because, you know, how does your community interact and how do they fit in? Because some of what you do is kind of, you know, back in security, making sure these devices are up to, you know, upgraded. Um, so how do you get community involved?
You know, what, how do you do that outreach for that? And is it, and is it important for them to understand why they should be do, uh, interacting with you? Yeah, all, all the above.
I think the most important part is starting with who is your audience? Where do they like to hang out? What do they like to do?
What do they like to talk about? If you start with really deeply understanding your, this community that you want to reach out to, then you can really meet them where they are. And so community could mean plugging into existing communities.
The, the, there's these Mac admins meetups, for example, all over the world. And we've started just reaching out to a lot of them being like, can we, you know, buy our next, you know, beer or pizza for your meetup? Or can we provide one of our office spaces to meet in?
We're actually doing one in our office here in Miami next week. And so a lot of it's just like, you can find where that community's already meeting and then you can help, you know, bring value, even if it's something, something small and minor, a way to just contribute to that community. Or you can create your own communities.
Um, and so for us, for example, LinkedIn, we post a lot of educational content on there. And so that's a community space that we're, you know, building that, uh, that's our own. There's also different Slack communities that we're in and things like that.
So it's usually a combination of, you know, slotting into ones that already exist or creating your own. But it all has to start from just really deeply understanding who you're trying to reach. And then it will become very clear and obvious kind of how to best reach them.
There would've been a time not too long ago that, that probably, that conversation wouldn't have started with LinkedIn. It would've started with X. Um, we're chasing what can, you know, what platform that should we be on?
And we're finding that LinkedIn is probably the best bet. Um, you know, do you guys do any outreach on any of the other platforms like masteron or, uh, blue Sky, Masteron and Blue Sky? We haven't invested much in yet.
They're still smaller. Um, and we have, we have surveyed our audience and, and tried to understand if they're worth investing in, and I think they will be at some point, but they're not at the top of the list at the moment. Um, X is still, I'd say it's less prevalent than it used to be in the past.
Um, I've heard a lot of mixed reviews on X. Some marketing leaders will say, you know, a lot of companies are departing from X, but individuals are still on it, so there's an opportunity there. You should, should still be there.
And then I've also heard the flip side where, you know, don't, don't invest in it. Uh, in my experience, the security community in gen in particular is still very active on x is from what we've seen. But I do think LinkedIn is, is the biggest one that's, you know, the most obvious choice and one that has just a lot of future potential that most groups are at least somewhat engaged on.
I feel like it's the most professional of them. I mean, if where it's really about professional content. Yeah.
Um, you know, and we all know that recruiters looking for to hire are pretty focused on it. So I think that they have found their niche and they're serving us all very well. Yes, definitely.
Thank goodness for them. Yeah. So, You know, I like to talk about, um, vulnerabilities, um, and software vulnerabilities.
Uh, and I know that you guys have, uh, some vulnerability patch management. Can you talk a little bit about what you guys are doing around vulnerability, you know, and, and automating the patch management? Yeah, so this is one of the most interesting recent launches that we've had.
Uh, we released vulnerability management a few months ago, but what makes it really unique is because our, you know, our starting point as a company was with device management. So generally with the way that vulnerability management works is, you know, so the security team will flag a vulnerability in their tool, and then they'll kind of throw it over the fence to it to be like, okay, fix the problem. Which often involves patching, you know, an outdated version of an app.
But because we have MDM and vulnerability management more consolidated and unified in one platform, there's all of these incredible automations and much more speed and automation you can build into that patching process that makes it much easier. So I, I see it as it's a time saver, obviously, because you don't have this, you know, situation where you're throwing it over the fence to another team that then has to sort of pick up the pieces and figure it out. But you also reduce your risk exposure.
The faster you can get to that patch and resolve the vulnerability, then the less exposed you are to that risk. Right. So, time saving, yes.
But I think at the end of the day, the time saving and automation is, is really most valuable in the context of, you know, protecting the company from risk and reducing that, that window of exposure. And when you de deliver your software, you're delivering it. This is an enterprise, uh, solution, correct?
Yeah. I mean, we have massive large enterprise customers. We also have many small companies.
I mean, if you have more than 10 Apple devices at your company, you likely need a solution like ours because no IT or security team is gonna, you know, go around to each device and make sure that all the settings are in place all the time. And so, uh, we, we have many, you know, smaller companies that use the, the solution as well. And when you talk about device, you're talking about, um, obviously Macs and phones.
Are there other devices that I'm not thinking about? Yes. So it's Mac, iPhone, iPad, um, apple tv.
And then we just released Vision as well, which there's some really interesting vision os use cases that are emerging. It's, it's certainly still, you know, the smallest of all those different categories. Um, but there's some incredibly interesting kind of use cases, um, in like aerospace, for example, um, around Vision os.
And so that'll be, uh, a fun one to kind of see where that goes in the future. And what about the public sector? I mean, does a public sector use, um, you know, apple phones and Apple Endpoints that might be air gapped?
You would be surprised? They certainly do. Um, and we do have public SEC sector customers.
I wouldn't say it's the, the largest base of customers generally, uh, customers. I mean, we, we serve anyone who uses Apple, right? But a lot of our customers tend to be companies in technology.
Um, because generally any, you know, modern tech company is gonna be, they're gonna have MacBooks for everyone. It's just a, a, a trend and it's something that modern companies do. So that's definitely a huge use case.
But there's also other use cases like retail stores with, you know, thousands of iPads or iPhones that they use for checkout and things like that. I didn't even think about that. There's a lot, right?
There's a lot. Yeah. And then you start really getting at, when you're, when you're at that edge, it becomes even more important that those vulnerabilities be patched so quickly.
You know, a soft code level vulnerabilities are taking about a hundred days to, to get remediated, uh, per company. Wow. Yeah.
So That's not gonna work. That's a hundred, a hundred according to Sonotype 185 for government. Wow.
It takes a while. I mean, there's, you know, in terms of code level there, we're at about 250,000 vulnerabilities. We'll probably get another 50 to 60,000 this year.
Um, some people are still downloading old versions of Log for, shell Log for j uh, and, and building out solutions around them, which means, um, apps that's running on your Yeah. On your, in your Apple devices. So it's a, it's, you're, you're taking on a pretty big challenge.
And we do something similar. We're, we're into the vulnerability management space as well. So it is, um, it, it's worthy, a worthy, um, cause and I think people should be more serious about it, to be quite honest.
I think that there's some com they're complacent and really thinking about how vulnerabilities could impact an organization and their customers. Well, and remember the day when we were all in the office together and you had your IT guy who came over and did your updates and did all that. And now you've got people spread out all over the world that work for your company.
How do you make sure, I personally, I'm not a Mac user, not a fan, but we do have, I have an iPad and an iPhone and an Apple tv, no vision, but knowing my husband as well as we do Tracy, and it's probably a matter of time before he's got something like that hooked up in our house. But, um, yeah, I mean, how do, how do you, how do you secure your entire organization when everyone's remote? Um, that's, I know that's a big question we've talked about around here for sure.
Absolutely. Yeah, it's critical. It's not a, it's not a nice to have, that's for sure.
So you said you went from a very interesting childhood. I might have. That's pretty, you said you lived in Mozambique?
I did, yeah. In Northern Mozambique. Very, very remote part of the world because my dad's a pilot with this nonprofit.
Basically they go to parts of the world where it's impossible to get around. There's no roads, or the roads are very unsafe, or there's terrain or mountains or you know what, for whatever reason. So he has a flying doctor program and just generally supports even just like development groups that are trying to, you know, build a resort on the beach somewhere.
You know, it could be anything. Um, he's flown politicians and they'll have flooding, he'll fly supplies, you know, just whatever you can imagine. But that's what that nonprofit does.
And so, uh, by nature of that, we always lived basically in the middle of nowhere. So were you homeschooled by a ticket? I have done every form of school.
You can imagine. I homeschooled as homeschooled as a kid. Um, I went to a little private, like elementary school that kind of the, the foreign families put together.
Um, and then I did some online school, and then for high school I actually went to boarding school in Kenya. So I would fly there for three months for high school, and then I'd fly home for a month, fly there for three months. I did that throughout the year.
Um, so spent a lot of time. Kenya's an incredible place. Um, and I absolutely loved, uh, boarding school.
But yeah, so when I, when I went to college, it was like just kind of another school. It wasn't, you know, this big thing that it was for many of the other kids, but it was all an incredible experience. I wouldn't absolutely wouldn't change a thing.
I think growing up in a different part of the world, you just have a different baseline of gratitude for what you have when you've been around your whole life. People that have nothing, many of which are the happiest people I've ever met, by the way. And, and, uh, yeah, you just have a different perspective and, and worldview of, of, you know, yeah.
Like success or happiness or how big the world is. Um, and so, you know, challenge hardship, all these things were just amazing lessons that I learned as a kid wouldn't change a thing because it just, you know, made me who I am today. Yeah.
On the happiness scale, I think that they, they brought that out recently. Um, I think the Nordic countries were on the top and the US was way down around 35 or something. We didn't even show up on the happiness scale.
It's a lot shocking. My mom is actually born and raised in Norway, so half of my extended family is there. I I went there many times as a kid, and I can attest they are very happy people there.
It's a wonderful place. But it's also hard to compare, right? Norway is, I think 5 million people.
And so you're comparing that sample size to the entire us I think it's kind of an unfair scale. Maybe. So maybe we should do it by state.
Yeah. I don't know. I'm just, I'm just chuckling.
'cause I remember the whole Norway rakes, their forests comment wasn't that Norway that was referred to for fighting fires because they don't get fires because they rake their forests. I didn't, yeah, they rake their forests. That was a, that was a brilliant comment made by the, the, uh, commander in chief at the time, a few years ago.
And the current, um, during the forest fires in California, he told Gavin Newsom the governor, well, you know, we need to be more like Norway because they rake their forests and that image of these woman, these people that look like you blonde and fair skinned out there with rakes doing their thing. I mean, I've done a lot of hiking in Norway. I, I bet looked, oh, it's beautiful.
It is beautiful. But the forest looked relatively unbreak. So It, I don't Recall, I don't recall them picking That tightly.
I digress. That was, it just made me chuckle. It's so what was it like, I'm serious.
Come to visit you went from a very remote, uh, childhood. Very remote, yeah. To LA What, what, what school did you go to?
It was a tiny little private school you would've never heard of, which was for the best because it would've ended up at UCLA, it probably would've been incredibly overwhelming. Oh my goodness. Yeah.
But what school? I'm from there. Yeah.
It was called Azua Pacific, so it was out. Oh yes. Uhhuh of course.
Great place to land coming from the middle of nowhere. Absolutely. Um, but still a transition of course.
Like wow, I think it's a city like la Absolutely. Yeah, exactly. And then I lived in LA for probably 15 years, you know, after I, after I got there.
Um, had a great experience there, but it was definitely a big transition coming from Africa. Um, and yeah, there was a lot of things that stood out to me. I think the biggest thing I learned as part of that, that transition was that being an outsider is actually the greatest superpower you could possibly have.
And I had, you know, classmates of mine that moved to the US and they would sort of hide their background or try to fit in or try to be like everyone else. And I did that to some extent, but I think I really embraced just like my unique story. And I found that I would tell people about it and they'd be like, whoa, that's so interesting.
And it really just helps you stand out. And I think that applies, you know, has applied to my entire life. You know, oftentimes in, in the tech world, in the security world, in the business world, I'm often the only woman or certainly the only one with the, the growing up background that I did.
Right. And these things all just make you stand out. And I think if you really learn to embrace those and love the things that are different about you, they can become, they can make you so limitless because you're not like everyone else.
And I think a lot of people, you know, give that away and try to hide it or try to be like everyone else. And it's, it's, you can actually be, I think, very successful by embracing what makes you stand out. And so that's really what I learned as, you know, landing in the middle of LA from the middle of nowhere was, you know, I can embrace that story and really use it to, you know, just make me stand out and be a more interesting person.
I think it speaks idea. Yeah, it speaks to the broader DEI conversation that we are, continue to have, um, you know, what does it mean to be diverse and inclusive? What, you know, what, what are we really talking about?
And maybe it's not using particular pronouns, but maybe it is having a broader knowledge of what the world looks like. Mm-hmm. And I don't know if all Americans have that broad of a knowledge, what the world looks like.
My, um, my, a couple of my in-laws, um, who, you know, pretty much stay in the suburbs of Chicago, ended up going to Amsterdam. And they didn't know how to use the public transportation. They had to call their daughter to figure out how to use the public transportation.
Right. Um, to me that is a lesson in, in being, in being diverse and inclusive because now they're experiencing a life that's so different from their own, that it gives you a broader perspective. I know I went from LA to New York.
Um, I spent the first probably two weeks with my heads looking straight up. 'cause I couldn't believe how tall the buildings were. Since you don't have tall buildings in LA because of earthquakes.
Mm-hmm. Um, did that make me more diverse and inclusive? It taught me something.
It taught me how other people live that somebody lives at, you know, 50 floors up. Which to me, it just blew my mind that that was their, their life experience living up in the sky. So, you know, I think that, uh, and, and even in software and, uh, as few women as there are in technology, and many of them do go into the area that you're in in marketing.
And I think that's a, a, an amazing place for women to be. 'cause we're better at communicating, to be quite honest. We ha as women in those roles, especially if you're trying to talk, speak to men, mainly men, you have to have a diverse, um, attitude.
You realize you're not selling to yourself. You're selling to somebody who doesn't look like you. And I feel like that conversation is so important and we don't have it because we get caught up on the wrong topics in diversity inclusion.
And I don't think d and I did us a whole lot of good, it certainly didn't include how much money is invested in women technology or women, women owned companies. Um, and I don't know if it increased the number of women in, in c-level positions around the world. Um, but we, we do have to have a bigger, broader conversation about how we're different, even if it's between people who live in New York and people who live in Alabama.
Yeah. And I feel like we should have some sort of a, I don't know, a job corpse or something for kids outta high school where they can go and live for six months somewhere completely different in the, within the United States. Mind you, you know, you're raised in LA go live in, you know, someplace completely different.
Like maybe Huntsville, you know, Alabama. Wouldn't that be an interesting project? That is really interesting.
'cause it's like the ability to put yourself in someone else's shoes is, is the, the core of it. And I think that's a transferable skill, right? Like, I feel like I can connect with almost anyone because I grew up around so many different types of people.
My high school was a international school with every nationality you could possibly imagine. And so I know that I can find some common ground with absolutely anyone. And I think that's a transferrable skill.
And yeah, if maybe you gave people those experiences to, to go around and see how big the world is and find some connection in some unfamiliar places, then they would realize that that's, you know, possible anywhere. I think that comes out in your website. Wow.
Honestly, I do. I think that that comes out in your website. I think you, it showed that you were able to listen to your community and to understand the brand that you had to keep up with, which is Apple.
Yeah. Right. So that experience has translated into your ability to produce a, a, a brand and a product.
Not that you are producing the product, but the brand is so important to the product. And I'm sure you've been driving that, that shows that you've listened and that shows you, you can, you can be a thousand, you know, a thousand different people, right? Mm-hmm.
Yeah. No, it's so true. That's such an important skill in marketing specifically.
And I think a lot of companies, I think every company struggles with this, where especially in marketing, you're, you're, you're preparing something, you wanna put something out, you wanna tell a story. It's like you want the story to resonate with you. You're always kind of dealing with your own bias and you really have to go outside your four walls or else it's just gonna be this like echo chamber that doesn't resonate with the, with the audience.
And so, yeah, we're constantly creating things that, uh, it's not something I would've created for myself or, you know, sometimes I'll, I'll send things to people for review and they're like, I wouldn't open that email. And I'm like, it doesn't matter. It's not for you.
Mm-hmm. Exactly. Exactly.
And that's because of your background. I really do believe that. And that's why you've succeeded.
So, so I mean, you, you've obviously achieved some serious levels of success in this, in this space. And I, when you, when you explained your background, it was like, no wonder because the ability to listen and to, you know, pivot and to understand, because when you have a diverse background like that, that's what you learn. Yeah.
It's true. Yeah. And I think, um, coming back to the, just the DEI conversation you were talking about earlier as well, it's interesting.
I think a lot of companies try to check the boxes, uh, you know, benefits for women or, you know, all of these sort of logistical things to try to support the growth of diverse talent. Right? But I think the answer is a lot more nuanced than that.
Maybe it's the skill of, you know, putting someone, your, being able to put yourself in someone else's shoes. But I think it's more about creating a culture of, of openness and connection and leaders being able to kind of tear down their own walls and connect with someone else. And I think that's really the difference that I've seen at companies that thrive in that, you know, diverse thought versus the ones that, that don't.
And so maybe this sort of broad, you know, worldview is, which I do think is more, you know, common in the world probably than it used to be in the past, um, can be a driver of some of that more, you know, open connection and, and the actually accelerating diversity and leadership versus some of the more traditional things that, um, that are helpful of course, but may not be the, the answer to really moving the needle. Yeah. I think the way we put DEI together in a lot of ways within universities and businesses, and yeah, it was a checklist, right?
We do, we have to do this, this, this, and this, instead of being more global about it and trying to, like you said, get people to connect with one another and not put labels on everything, because that's just frustrating and can be confusing as a, a person that is older, um, having a queer child who is an actor and lives in New York City now grew up in Colorado, but went to very diverse school programs, which they were within the, the state, but they were schools that brought kids together from every, every place around the state to participate. And it made her, it made her very much, um, it, it gave her the ability to, to really relate to everybody. Just like what you're saying, you, you learned it in a foreign country.
But we were able to provide that to her and her local education. And I think it was hugely important. And I just think if we did more of that and did, did less of the, the labeling and the check boxes, that's what people hate.
They hate being told, here's your list and you have to fulfill it. Right. Nobody, that's I think what people are pushing back on.
So I I, I agree wholeheartedly with what, what you're talking about, for sure. Yeah. And I think mentorship is really important as well.
And coming back to what we were talking about, about being, being an outsider and learning to kind of use that as an advantage. Like this is what I tell young women that I mentor in, in leadership as well. Sometimes they'll come into a conversation and they'll be like, it's so difficult being a woman in the business world, or in the tech world, or the ex whatever description.
And I always invite them to reframe that a little bit and ask themselves, what are the ways that this can make you stand out? Like, what are the ways you can turn this into a superpower where you can step into something that's really authentic for you? And use that to, to feel confident and, and thrive and really stand on your own and not just be one of the crowd.
Right. Maybe that can be an advantage. I think just inviting some, some reframe around that as well.
Um, yes, there may of course be challenges too, but, you know, that doesn't mean we need to ignore some of the positives that we can lean into as well. And I think that's something that I, you know, certainly did when I was younger that I learned through this whole experience that's really, really served me. And, you know, I've, I'm, I still learn that lesson sometimes and, and, uh, I'm definitely not perfect at it, but I think it's, it's a useful one to just kind of think about the opportunity a little bit differently.
That's amazing. To, to take that idea of, Hey, I'm the only woman in the room. I'm gonna, I, I stand out.
I've already got a foot up. What can I do with that? Yeah.
I think that's a spectacular analogy. I'm gonna share that with my child. So why don't you tell me, why don't you tell us a little bit something about pavilion?
Yeah, so Pavilion, I'm, I'm really excited about this. So I just took over a couple months ago the, to be the Miami Chapter head. I'm co chaptering it with, uh, with another woman, a friend of mine.
Uh, but Pavilion is a, a global tech go to market community. So I think they have over 10,000 members all over the world. They have chapters in every major city in London, New York, Denver, you know, everywhere, uh, across the world.
And it's just a place for, you know, tech leaders to come together and learn from each other. And so I took over the Miami chapter recently because I feel like the tech community here is so big, but so disconnected. Like no one knows each other.
And a lot of people in Miami work remotely for companies in New York or San Francisco. Obviously we have tech companies here too. Ji's one of them.
We have a big office here. But a lot of the tech community here feels like there's no tech community, but there is, they just don't know each other. And so that's what I'm really excited about creating here, is this opportunity to come together and build in community and learn from each other.
I think even sometimes just the, the, the simple act of knowing that you're not alone in something can be really empowering. And so just giving folks a space to, to come together and talk about challenges and what they're overcoming and what they're working on, um, is really gonna strengthen the whole community here. And I love living here in Miami.
I wanna be here for a long time. I want Kanji to continue to, to grow and thrive here. And so I want the tech community to thrive alongside it as well.
I think I should join. It sounds like something I should do. 'cause I'm in New Mexico.
You should. And I feel that all the time. Yeah, Yeah, yeah.
It's like, and they ha I wonder, I don't know if they have a local cha, you'll have to look up the local chapters, obviously, but there's also the global, like Slack you can, can connect with anyone there, and they have courses and stuff as well. So definitely recommend. It's, it's been so impactful to me in my own career As well as mentors.
Absolutely. Yes. Who has mentored you along the way?
So many, so many people. I think, uh, a moment that stands out to me actually is, uh, I had a mentor when I was at that first tech company I worked at where I was the first marketing hire. We were like 12 people and really had, you know, it was very early, was learning everything along the way.
And I remember going through with her, she was a CMO, and I remember going through with her the things that I was working on and just being like, am I even on the right track here? Like, I didn't feel very confident in what I was executing on, because I just didn't have the depth of experience to make sure that it was right. And I remember presenting it all to her, and she asked a bunch of questions and she was like, oh, she's like, you're doing all the right things.
And that just gave me so much confidence at the time, that was exactly what I needed to hear from her as a, an incredibly successful CMO, um, to just be able to like, move forward with confidence and continue to build from there. Um, and I actually reconnected with her recently, and I hadn't talked to her in many years. And it, that was so special to get to, to talk to her again, because I think, yeah, just having, sometimes it's not even the tactical advice that someone can give, it's just the, you know, the confidence that you are on the right track, and that helps you continue to think creatively and be able to keep building.
Um, because I think if you're in a, a nervous mindset, it's hard to, to think big and it's hard to be creative. And so just getting some encouragement from outside the company, from someone who's unbiased, um, who's just there to help you. Incredibly impactful.
Have you ever thought about writing a book? I have actually. When I was like, maybe 12, I wrote a book, which I have no idea where it is.
It was like a fiction book. I don't even know what it was about. I'm pretty sure my grandfather has it, and he still asks me all the time, um, if I'm ever gonna publish it.
But I, I would, I really like to write a book one day. It is on, it is on my, my vision list, but, um, I'm not actively working on anything, but I just feel like I have a lot to say. I think you have the title of author in your future.
Absolutely. Yeah. Thank you.
I believe you have probably a lot to teach us about marketing and diversity and listening and building community that so many of us could learn from Absolutely. Beyond just business, beyond just business. I'm talking just culturally, you know?
Mm-hmm. Um, every, every single one of us need to understand right now, especially in the US how to reach out to community because we're, we're not a community anymore. We're, you know, so divided.
Yeah. Um, and we sometimes when I hear people talk to each other, it's so vile. Yeah, right.
We have forgotten to just try to see the other person's side. I don't wanna look at the other person's side. I admit I am part of the problem.
I'm trying so hard. Um, but yeah. Um, listening and learning, uh, I think, I think would be your, I think your insights would be, make, make a great book.
Thank you. Yeah. But no, I agree with you.
I think people, I think people, especially online can be just the, the tone and the, the, you know, aggression sometimes just surprises me. I think people show up differently online than they would in person too. And it's easier to really poke at someone, you know, from behind your, your screen.
And yeah, it's challenging. It's challenging to be visible today because there's always gonna be someone out there who's, you know, happy to, to point out the flaws or tear you down. And I think that's really challenging for, for a lot of people.
And I hope that, you know, something changes in the way that we connect with each other to, to make it, you know, help people build each other up. But that's why I think community is so powerful, because there's actually so many people out there that are willing to help you. And I heard from, you know, someone told me this once, they were like, it's actually like a gift to that.
Someone can, you know, people feel good when they're able to help in a way that is meaningful to them. And so if you're able in the right, you know, context to ask someone for help, like, don't always see it as like, ah, this whole burden I'm having to ask someone to mentor me. Or having to ask someone for advice on this challenge because it's actually, you know, a gift to that person.
Because for a lot of people, it makes them feel really good to be able to help. And just hearing that made it easier for me to build my own community and ask for help, because it's a hard thing to do when you, you know, you're asking someone for something. But, uh, it can create amazing connection and, and really help that person feel good as well.
You think women have a harder time to ask for help? Oh, a hundred percent. Definitely.
I do too. I do too. I always, I think that, I think we feel like we're supposed to do it all, and I have to let go of that and ask for help.
And sometimes I don't ask for help soon enough. Yeah. And I'm the exact same way.
Actually, my, my personal theme for the year this year is leverage, which is not doing everything myself, essentially really leaning into for my own team that I'm running right now, how can I empower them to be, you know, future CMOs and future leaders? And, um, and instead of focusing on, you know, the task at hand, how can I play this longer game where I'm building them into, uh, yeah. Future leaders that is only gonna make the whole team better, right.
Or, uh, or even in, in my personal life. Like, there's things I just don't have to do either I can outsource them or I can ask someone for help with them, that a lot of times I just tend not to. And so that's, that's a big theme for me this year too.
And definitely very much still a work in progress. Wow. You know, we're running outta time.
Tracy, I keep trying to stop you and you keep going. I, this is a fascinating interview. It's an Sylvia, you are really an amazing example of what women can do in technology, and it's been a absolute pleasure.
It has been. Tracy, you wanna ask your question before we wrap? One last question is, do you have a book recommendation for us?
It can be any kind of book. It doesn't have to be a book on technology, but if you have one, it can be What's your fa your last book you read, or a book you, you, you think about often? I have like 10 that are coming to mind.
I can, I read a lot, but I'll give you the last one I read, which is the first one that popped into my head when you asked the question. Um, I read Earnest Hemingway. I know this is an out there one, earnest Hemingway.
It's called a Movable Feast. And it's all about his early days in Paris and just wandering around the city doing his writing. One of the quotes that stood out to me was, he was like, there's nothing in the world like walking down a flight of stairs after you've done your work for the day.
And then he was like, then I'm free to walk around Paris. And I just loved the framing of that, where it's like, you know, and it's not just about doing, showing up and doing your work. It's like when you've done the thing that day that really mattered, and then you get to walk out your office or walked down the stairs and it's like, then you're free because you've done the thing that really mattered.
It's almost like an unburdening. So very random book recommendation. But I, I like to, uh, go off the beaten path of it.
I'm gonna check it out. Yeah, that's great. I'm sure it's amazing, especially if he's getting to walk around Paris, one of my favorite cities in the whole world.
Ditto. It's beautiful. It'll like transport you there.
I love Paris. Well, thank you both for, uh, this amazing conversation, Sylvia. Um, I'm so grateful for you and, uh, Nina, she's lurking in the background.
I always have to thank those folks who find us because, um, they bring us these amazing guests for, for our, uh, podcast webcast here. So thank you for that. And, um, everybody, just thanks for tuning into another episode of Textron Women.
Uh, we look forward to having you back in the future and keep watching Textron TV today. There's lots more stuff for you to watch. Thanks again for being here.
We'll see you next time. Hello and welcome back to Infrastructure Matters, uh, episode 80, uh, welcome Keith. Um, and I think our, our partner in the crime, uh, Kimberly is, uh, is out this week.
Yeah. So that means I have to ask you, where in the world is dying? Well, I'm still in the Balkans, that's why we're gonna be till mid-June that I'm heading over to Rome, so Oh, nice, nice.
And this half year overseas. Yeah. And then, uh, then we come back.
So, uh, lots of fun. And this, it's getting the weather's real nice here and we're on the beach, uh, on the Adria, so good stuff. How about you, Keith?
Where, whereabouts are you? Where Just left? Uh, I actually just left Kimberly.
She is, uh, off doing Tech Field Day, uh, and learning all out about AI infrastructure from some of the biggest AI infrastructure companies in the world. But I am back here in Chicago, at least for the next couple of weeks. So you'll be in Rome just in time to, to greet the new Pope.
So that, that'll be, that'll be good. Tell 'em I said hi. Yeah, absolutely.
Um, and so, um, interesting week, um, you know, there a lot of people are looking at what, uh, how the tech industry is gonna weather all the things happening with, uh, the economy, um, the geopolitical instability, the, the new, um, administration in Washington. Um, but ServiceNow, S-A-P-H-P-E all turned in very interesting numbers, uh, uh, good numbers, uh, ServiceNow beat expectations. Um, subscription revenue grew 90% year over year.
Um, the shares went up 10%. SAP, uh, reported Q1 cloud, uh, Q1 cloud revenue rose 27%. Um, their backlog grew 28%.
HPE stock outperformed, even though they had given pretty grim guidance last time around, uh, shares climbed, uh, almost 6%. Um, and so, uh, so there is, the market has been doing good the last couple days. Uh, so it's, it's very interesting to see how, how things are, are going.
What, what do you think of it? I think us Google Cloud news as well. Um, Keith, Yeah.
So the, uh, just a note on HPE, I'm really surprised. Well, I'm not surprised that Elliot is going after Antonio O Neri. Uh, they won his head on a platter.
Uh, I, I think it's fair to say, and both of us have covered HPE for a really long time. Uh, he is generally really loved, uh, amongst, uh, he, And he's also not, they're gonna have, he's not an easy guy to take down either. We both know Antonio pretty well.
He is, uh, he's not gonna, We, we know him pretty well. He's a tough, he came up from the trenches. He was, he started there at Support Desk.
I think that, I think, uh, Elliot is going to have a nice battle on their hands. But, uh, Google Cloud, uh, and I'm zero in on Google Cloud numbers, but, uh, on the macro Alphabet had outstanding numbers. 2 billion.
Uh, but if we look at, uh, Google Cloud, specifically the infrastructure part of Google, they're up 20% year over year. Um, and That's good. But it's all going right out the door as far as I can see.
They're are, didn't they say they're gonna drop 80 billion on CapEx? 2 billion in income. 2 billion on.
And I think, uh, I think one of the things that get hidden in the numbers that while Google Cloud or Google Big is making the investment, and Google Cloud kind of takes the brunt of it, most of the most Google services run on Google Cloud. So it is not just a cloud only expense that is spread throughout all of Alphabet, because Google Cloud is the service provider of Google. So, uh, what I thought was really interesting, uh, we were at Google Cloud actually earlier this week.
Me and Kimberly were, and we're living, listening to the product team for their accelerated compute. And the product manager was saying that the demand, I asked him about, uh, Jensen won sws, hey, H one hundreds, H two hundreds, basically, hopper, you won't be able to give them away. He's, he, he, uh, let out a sign.
And he said, well, the product manager for that product, you know, was, you know, having a, uh, a bit of a heart attack. But he said that, but he, he said that they've seen, not, not just reduce demand for it, but increase demand, and they have the latest, uh, Nvidia chips. They're one of the only cloud providers to offer instances direct directly for the GB 200, I think it is.
Mm-hmm. Yeah. And they're saying they're seeing great demand for all of it.
So the, the, I think this is a gr good indication that the H one hundreds, H 200, those depreciation schedules for those, uh, for those chips are not going to be at risk. This is a really interesting, uh, uh, seeing this play out. Well, and I think part of that is there's, you know, just getting, uh, affordable compute time for AI is the challenge.
And if Google prizes them, right, they should have no problem getting, uh, you know, selling hours on those. And that's was exactly the, uh, product teams kind of reply to us. Not only is it priced right, it is where they need it, where customers need it.
Data has gravity. The gb, the G 200, I'm sorry, the B 200, GB 200 are still relatively, uh, has light demand. They said they're only been able to accomplish, uh, uh, accommodate small clusters of 32,000 GPUs.
I thought that was interesting. 32,000 GPUs had been the, the ceiling just a couple of years ago. Now, 32,000 GPUs are, are considered small.
Mm-hmm. But, uh, that the availability of H one hundreds and H two hundreds is so pervasive that this is where the, uh, demand is at. And this is, and it's where the customer's data is at, and it's available in, you know, in every region, et cetera.
So it's, it's, it's, it's, it's interesting seeing the, the drive of technology hit supply chain and the reality of enterprise it refresh even at the hypervisor skill. Yep. Well, and, and, and in my analysis, 'cause I've, I, I've spoken a lot, uh, to CIOs about Google Cloud and the real challenge that I get, I, I, I, I've received calls from, from, uh, CIOs saying, I really want to go to Google Cloud.
They're the most modern cloud. They, uh, they came a little bit later with a lot of their abstractions and a lot of their concepts. So they were able to, to create more refined, you know, more elegant, um, uh, you know, cloud architectures.
Uh, and, and I agree it's one of the best integrated, easiest to use clouds that there is, uh, are, but they just can't get the talent. Uh, there's, uh, because it's the number three cloud, the talent base is not there. You can get a ton of people who know AWS ton of people who know Azure, um, getting the, uh, from service providers or hiring talent or wi sourcing from anywhere.
They can't get enough people to do Google Cloud. And that's always been kind of the holdup. But I think now the real advantage is if you have great, a great AI capability, um, and you've got affordable ser uh, cloud services, and you actually have available capacity, you're gonna get business now.
5 is. It is, uh, the, it's safe to say they've not just caught up for a little while. They were leading until maybe oh three came out from open ai.
So one of, I think this time last year was they Were in the leaderboards the last, uh, month or a half or so for sure. I hadn't even seen the new ones yet. Yeah.
And I, I, I think a year ago I talked to a CTO and I said, Hey, why, why aren't you using Google Cloud? Uh, ai. He laughed.
He was like, Google's AI is a joke. I don't think, I don't think it's a joke. I don't think customers are considering it a joke anymore.
And the numbers bear that. Yeah, no, it's, it's interesting. So, uh, Google Cloud is firmly in the game, uh, but I think they have their, their work cut out from the, the ever pull out of number three is really gonna be the challenge.
And that I don't, and Google's not used to. They don't like being number three. They're not used to being number three.
They're used to be number one. So, um, but I don't think you have to worry about Google Cloud going into Google grave graveyard anytime soon. So, good, good for them.
Um, in, in other news, so the, uh, management consultancy, AIX Partners just issued a, a major report. They were studying the weakness, the susceptibility of the, of the top, top public software companies, um, against AI disruption. So someone comes in and creates a born ai, you know, AI native version of ERP, for example, or whatever.
I mean, because the broader shift is gonna be away from apps and more to agents, agents are gonna do more and more things for you. You're just gonna go to the agents, say, I wanna do this, that, or the other thing. And you'll be using them in as versus apps, even though an agent, of course is still just an app.
Um, just, it's just a different way of, of packaging it. Uh, they are saying that, that the, the top a hundred software firms, or most of them, are vulnerable for imminent disruption by these startups. And for example, I was talking to the founder of, um, hyper mode last night.
Um, they make a enterprise grade agentic framework that you can build, run, and manage tens of thousands of simultaneous agents of every flavor, doing all the interoperability use, using your knowledge graph. Um, and they have all the governing, they, they give you the control plane to actually do the, the digital labor management across tens of thousands of agents. This is a, you know, they, they rethought the whole problem from the ground up, and they're not trying to, uh, fit agents into their existing AI frameworks or their existing enterprise suites.
So you've got, you know, Oracle and SAP and ServiceNow and all these companies who, who have gotta make, they, they can't, uh, reinvent everything for AI because they, they can't change all those applications that they have. So the, the born native companies, the born AI companies, uh, the as theory goes, have an, may have an inordinate advantage. And, uh, and so that, that's gonna be interesting to watch that can really change both the public markets, uh, and the tech industry.
If that turn, if that bears out, Yeah, I can, uh, I can s share firsthand, uh, story of how a hundred year old manufacturing company is actively moving away from SAP to an agentic AI model of where they're having the, the, they're having, you know, kind of this immutable service bus that says, oh, once a transaction is, uh, uh, made on the service B bus, every, all my different SAP modules that I had before, instead of having SAP do that functional work or the workflow going through SAP, it becomes a, a agent workflow. So, uh, you know, they have some challenges around, you know, uh, SAP is deterministic and you know, what you're gonna get each and every time. So, uh, finding out what parts of this workflow needs to be, uh, deterministic and what parts of it is, uh, kind of the, this AI or problem or the human almost.
I, I, I, you know, both you and I posed this question, I think we're at the same conference, and we asked one of the, uh, one of the major SaaS providers, you know, what's to stop someone from taking agen, uh, AI solution a a agent and replicating what you do? And they were pretty confident that they would not get disrupted by ai. But I don't know, I'm starting to see a little, I'm starting to see a few cracks in that, in that arm.
I'm, I'm seeing ai, uh, really, uh, as we've studied agentic ai, we just did a big market overview of the top platforms. We also did a deep dive on agent force for Salesforce recently. com.
Um, we found that healthcare is one of the top use cases because it's been very resistant to RPA and a lot of other automation because there's such a huge body of knowledge you have to train for. While these models, AI models, gene AI models are trained, uh, even they, there are these big health models now that have studied all of it in all the terminology and all the different things in the ins and outs of the industry. And, um, and they studied, you know, thousands or millions of, of patient records.
Uh, they, it, it, a healthcare is now very easy to, uh, tackle with AI because it can take all the different domain knowledge and all the different, you know, hospital and healthcare management knowledge and, and actually do things and answer questions. And there, and, you know, the, the, the big problem is it's still only about 90% correct. About 10% of the time it's still wrong 'cause it's a probabilistic scenario, but all that's gonna get fixed with consensus based models that, you know, over sample until you get the right answer and grounding and all that.
But yeah, it's fascinating to watch. But speaking of he, yeah, And I just, Yeah, sorry, go ahead. Before We go move on to healthcare, just to back some of this up with data, the door ai, uh, AI code assistant report is out kind of the results of what happens that now that we have these code assistance en mass in the market in the increase or lack thereof of productivity, I think a key vector that's missing from the report is kind of this gap that these assistants can fill.
So the experienced teams are seeing only a 2% increase in productivity effectively from using adopting AI assistance. One of the things that I would love to see, and you hinted to that in the healthcare, uh, part of this conversation is what happens when you team these AI assistance with non-practice developers, non-practice, uh, healthcare professionals where it makes sense. So IE you know, me creating my latest application, I'm not a developer.
I don't consider myself a developer, but I'm able to develop because of these AI assistance. How do we begin to measure, uh, productivity increases, uh, from when companies are just, and employees are just incapable of doing something? And now what can someone who's adjacent to these areas of discipline, what happens when you give them the same age agent, uh, tools I'd love See On, on how, how these tools impact productivity.
Exactly. Well, we know that, you know, Keith, you and I know, you know, having been developers, um, we know there's, there's a whole body, there's a whole bunch of stuff you have to learn, you know, you know, avoiding, you know, watching bgo notations. So you, you create computationally sane algorithms that, that when you give it a bunch of data, they don't, they don't, they know stall and die.
All these things that are, they know code, um, you know, business, uh, analyst developer would not ha have any of that, that background in it. And they could easily develop something that's not workable in an enterprise environment, works great in the lab, but doesn't actually work in the field. Um, but these ai, uh, uh, code generators, these agents, they know all those rules, and you just explain in plain language, which you want.
And in fact, that's what we're seeing with these agent builders now, is just, it's just a prompt. You're just saying, I need an agent that does X, Y, and Z and follows this, this industry set of rules and this policy, which I've just, I've included the policy document in this, build me something that can process documents according to all these rules and these policies, uh, and gimme outputs and drop that into this database. And, um, it will just do that and following all the best practices and the rules.
Uh, and, and, uh, so these agents are now proving very easy to build when they say you can build one in a in a couple hours, it's usually not even that long, is what I'm hearing now to harden and test it. Yes. That's actually where most of the work is to make sure that you've got determining if a human needs to be in the loop for the before the final answer, to check the final answer or, uh, what you're going to do.
Um, but yeah, the future of COPE building is, uh, developing applications and agents is writing prompts. It's very interesting, which it just humans, yeah, The, there, there's plenty of opportunity for, uh, folks to un who understand observability, folks who understand the logic to, uh, make a big change. And one of my challenges has been observability and the ability to make sure that the ai a, the AI agent is getting the right return from the LLM, which is not always consistently, it's non-deterministic.
So getting expecting that for, uh, uh, uh, uh, a response to be formatted in the way that you expect it to, and you code to, has become like one of my number one challenges. Yes. And we see, like NVIDIA's, uh, agentic framework, uh, has advanced log fi logging that explains why it did what it did, so that you can go back and say, now you gave us an answer we wouldn't, didn't expect, or we think is wrong, but explain it to us.
And, and you can go through its reasoning and see that, see, I think reasoning AI is gonna be very popular, these new reasoning models, because they can't explain, you know, why they came up with it, you know, so that, that's encouraging. But we were talking about healthcare and, um, Oracle had an unusual data breach. Um, they're generally considered one of the safest, one of the most reliable, uh, enterprise vendors from a cybersecurity perspective.
Uh, it was legacy servers. Oracle says, if you're on, if you're updated on everything, you're fine. Uh, but many IT departments can't be up to the minute on all patches and, and be everywhere.
And this was in legacy, but 6 million healthcare records were lost, um, on Oracle infrastructure, legacy servers, um, that, uh, were not patched, but, uh, you know, with mandatory, uh, cybersecurity reporting for, for, for public firms that they had to disclose. Uh, and that's, that's a, that's a black eye for Oracle for sure. Um, that given there are stellar record really, uh, for, for this up, uh, up to date, but it, and it's getting quite a bit of attention as a result, even though the breach is relatively small.
So it was this from their acquisition of Epic, or is this outside of Epic? Um, that is a good question. Um, it, uh, Oracle Cloud Classic and Oracle Health is what they're saying.
So I don't know if Oracle Health, yeah. So that's not, I, I don't think that, I don't think that would be considered, uh, the Epic. So obviously with them acquiring Epic, this is big, big news because, uh, they control, uh, or they, they host a good percentage of very large Percentage direction national Yes.
Um, uh, health records nationwide for sure. Um, but moving, moving on beyond that. So it's something definitely for CIOs to watch.
Um, the, um, is we're seeing, again, renewed. We, we saw a spate of announcements on, um, uh, AI vendors announcing just truly huge investments to show how serious they are about the space and, uh, and why people should partner with them versus the other ones, because of just the scale of the investments that we're super serious. We have the, the funds to really build, uh, whatever's required to, to create the, the next generation of models that are gonna dominate the industry.
Uh, all the vendors have been trying to prove that. We saw that with, um, project Stargate from, um, OpenAI where they're, they, they said they're gonna spend up to $500 billion, uh, with SoftBank pointing up a lot of that. Uh, well, we had another round of announcements.
Um, uh, the eu, uh, uh, has, which is generally considered very behind in ai. They don't, they're not really in the game at all. Um, and they, and, but they acutely feel it, they just announced, uh, the, uh, invest AI initiative, uh, $200 billion, which is a, or Europe a lot of money because they're, uh, it in Europe is very conservative.
Um, they, they spend wisely, uh, they wait too long. Uh, but they also have very good ROI numbers compared to the United States, who is, uh, where we're willing to be a lot more speculative about IT investment. They're not.
Um, but here we are with the EU out, out ahead, uh, whether a best AI initiative, $200 billion, that's, um, for helping companies and building the infrastructure, uh, to, to put, get on the, at least get on the map with ai. But that wasn't the big one at all. The big one was Nvidia announced, uh, plans for $500 billion in AI infrastructure in the United States.
So a big, big kudos, uh, you know, uh, to the, the Trump administration who's, uh, pushing with tariffs trying to get Taiwan, uh, based companies to invest more in the United States, uh, which is a critical hedge. If, if China does end up blockading or invading, um, Taiwan, that's gonna have a tremendous impact on, you know, Nvidia, uh, TSMC and a host of other critical companies for the high tech industry. Uh, it's a smart move.
The whole question is, is the regulatory red tape gonna be cleared out to actually do anything with that money? Because right now it takes up to 10 years to build chip fab here in the United States, and by the time you get it online, it's way outta date. And so that's why it's not done here.
So we'll see what happens if that, the announcements are great, but we just see what really happens. Yeah, and I think the, I'm, I'm really intrigued about this EU investment. We do need strong partners in AI and Different Yeah, exactly.
Yeah. And competition. We, we need a different vision for AI that maybe takes this EU centric, privacy centric focus to ai.
And I think if you, if you know, let's compare it to deep seek, if the EU can do with ai what the Chinese did with, uh, deep seek and move forward the, the ball without using our private data in the way that it's being used now, I think it's overall good for the industry. Justice deeps seek was. Yeah.
And I think, uh, you said is right. There'll be a, the, the EU will have a different take on ai, one that maybe is more respectful of privacy, uh, more careful about it. We'll see.
Um, and more regulatory friendly. 'cause that's where it really, you know, the, is one of the, the joke is that it's one of the greatest, um, um, the greatest outputs is regulations. Um, and that's what they, so, uh, you know, they're the reg reg tech heroes.
Uh, let's see what they, they do with ai. So I, I'm encouraged, uh, and there are some AI stories out of Europe, that's, to be honest, they're not big. Um, but this could make them big.
And so I wish them luck for sure. I mean, it's always good for the industry to have to see this, uh, but that's not all AI investment's not the only thing. Um, sounds like, uh, there is interesting things in Dell storage land, uh, Keith, can you catch us up on that?
Yeah. So Dell pre beat briefed us on this in a while, but, uh, there is no secret that companies like Vast Data are taking advantage of their architecture. VASH will tell you that this is by design, their vector services that they have, et cetera, are all aligned to being able to get into better training, et cetera, vast.
I know we're talking about Dell, but, uh, it is a note that Fast and, uh, super Mac Micro this week announced a what this super pod, this, this Nvidia type super pod that has eight, uh, uh, uh, eight, uh, gb, two hundreds, along with fast data, the importance of the, the importance to the Dell announcement that the AI data pack pipeline matters. You, you know, both of us will tell you we're no Kimberly Bates when it comes to the, uh, the ones and zeros of actually storing bits onto storage. But we understand the importance of the data pipeline and all these announcements across all of, uh, Dale's power lines from, uh, the power scale all the way up to the power of Max, which is their big iron, uh, nonstop run.
My most important, important workloads are getting AI enhancements from accelerators all the way to, uh, uh, partnerships around data lakes to help organizations organize their data and keep this data ready for ai, which, uh, I think both of us are seeing is consistently a problem for, uh, enterprises, which is making sure they have the right data for ai. There's this really interesting debate that, do I need to prepare my data for ai? You'll get two very different camps who do, do not agree, Sam Luis says, bring the data that you have, and others are saying, you need to organize this data.
And we're seeing the industry at large, the storage industry, these deals announcements play into that of, of being able to organize your data, get it ready for AI so that your, uh, that so that your organization is with in compliance and, uh, going at the speed that they need need to, at the same time to feed your GPUs and keep 'em, uh, as efficient as possible. Yeah, there's no question. Well, I mean, yeah, there a couple issues that organizations have.
One is keeping the, the, the GPUs fed. Anytime a GU is idle means you're, you're, you're leaving, you're leaving money on the floor, uh, you're, you're, you're cost is too high. But, um, then you gotta get, you have to have all the data that, the real issue is, is these context windows aren't large enough, um, to handle the, the, all your enterprise knowledge.
So where do you keep that and what format do you keep it in that's optimal to make sure you've got good coverage of it. Even if you have these models that have these large windows, they often don't pay attention to everything that you provide it. Um, and so this is why I was talking, going back to that hyper mode conversation last night.
You know, they're, they're trying to store knowledge in, in disc based knowledge graphs that can get as arbitrarily large as you want without har harming performance, uh, and making sure you're taking everything into account and you're not ignoring, you know, part of it just, uh, to produce a, an answer quickly. So yeah, there's a lot of performance issues here we, I think we have to, um, have to worry about. But yeah, storage is, you know, has this thing where it gets, it gets sexy again when we have, we, we enter new revolutions like the ai, you know, the whole Gen ai, um, and, you know, Amazon's famous for having what the up to 12 different types, models of databases that their, their cloud supports.
So for e every use case, but, uh, uh, storage is essential. And data gravity is, is still one of the biggest challenges in trying to say I want to build one AI infrastructure. Um, and with a rise of private cloud, we saw, again, a very sustained interest in our CIO survey.
We just got our data in around trying to figure out the best place to, to run workloads. And those workloads need to be powered by data, which is kept on storage. So interesting times.
Uh, everything's kind of in motion right now. Uh, and the JIA revolution. Alright, anything else to wrap up, Keith?
No, it's been a busy week. Uh, I'm sure, uh, Kimberly's gonna join us with plenty of data from AI Field Day, I mean, AI infrastructure Field day too, which for you, tech Field day geeks used to be called Storage Field Day. Now it's called AI Infrastructure Field day two.
And, uh, the range of companies from Google Cloud to Vast, I mean, not, sorry, not VA is in initial one, but, uh, Soine and store pool and, uh, the, the list goes on and on. I, Juniper Networks was there. Uh, the, the, just the variety of customers, I'm sure she'll come back with more data and more insights than, uh, one person can absorb.
Yep. So CAD, just next week, uh, I also have CIO chat, uh, every Thursday at 2:00 PM Eastern Standard time. Uh, stop by and watch, stop by and contribute.
Uh, and we will talk to you next week. Thanks everyone. Hey, everybody.
GPUs or political ponds and hey, we might even be tracking 'em around the world. You're watching Textron. All right, everybody, as we said, GPUs are in the news again, and turns out that, well, they're political pawns and we're using them that kind of set up trade agreements, and there was a whole series of things happening in the world.
But we have an awesome lineup of folks to talk about all this. Starting off with our czar of Silicon Valley. John Schwartz, how you doing, John?
I'm good. How are you, Mike? I'm well, I'm well.
You, you're looking brighter than ever, man. I'm liking this whole new camera. I'm trying to, I've been working on the lighting, the camera that Alan sent me is very nice.
It's a work in progress. All right. Uh, well, at least, you know, you don't look like, Or are we all working?
So that's good. We all are the day to day Yes. We're All, we're all a work in progress.
There you go. All right. Well, speaking of a work in progress and a whole award's joining us from, are you still in Texas or where are you today?
Austin, Texas. Yes. And we're getting our first triple digit, uh, day today.
I am not really mentally ready, but here we are. Exactly. And also in Austin, correct, Robert?
That is correct. Oh, Nice. Robert is, Yeah.
2 liter diesel engines and GPU export controls. And I care to admit Sounds about right. Well, Well, when we and the gang are always excited when we can bring our friends together who live in the same city and have never met before.
So it, it happens more often than we care to understand or admit, but hey, it's the world we live in. And finally, I'm Mike Ard, and I'm here in New York as usual, and we're gonna jump into this topic with John. John.
It's kind of crazy out there. I looked at the entourage, they went with the president to the Middle East, and it includes Jensen Wong and the folks from Open ai, and they were handing out contracts and gifts. Like it was, well, candy, what's going on here?
And, and, and has this just become the new norm or GPUs being held hostage for training and political Yeah, Like bargaining chips. Yeah. The, the, the Trump administration, I think sees these, um, these chips as, uh, literally bargaining chips and, uh, giving them some sort of leverage over other countries in terms of relations with other countries.
I think, was it you or someone here? We, we talked about this, that the tech beat has actually become like a politics beat. And in a sense, there were three things that happened in succession, and I'll go back to last week, where it starts with these federal lawmakers.
There's one in the house and there's one in the Senate, and they're moving forward with these bills that would require AI chips to carry geotracking technology to keep these sensitive chips out of hostile hands. Namely, they're talking about China. So there, um, was a chip security act, which was, uh, sponsored or written by Senator Toma Co of Arkansas.
And he, uh, wants to keep hardware from quote, falling into the hands of adversaries like communist China. And essentially he would give, the government would give the commerce secretary authority to verify location of, of this hardware. So then we have that followed by this week's news that NVIDIA's gonna ship more than 18,000 Blackwell chips to Saudi Arabia to help power this new data center project with a newly created wealth fund owned AI startup called Hue, I believe, and who was there in Riyadh, but none others in Jensen Wong to talk about AI and how it, like electricity in the internet is essential infrastructure for every nation.
So they have this project going on. So this was this project, or this deal was announced as part of this White House trip to the Middle East. And in, in, in a sense, Saudi Arabia is trying to enhance its AI capacity and strengthens its cloud computing infrastructure through foreign investment.
That deal happened, of course, a day after the Commerce Department officially rescinded the Biden administration's AI diffusion rule that would've placed caps on ship sails to most countries around the world, effective May 15th. So in a sense, it is a political football and the candies being handed out to Nvidia and open air open, open ai, open air, open AI among others. It, it's really hard to, to to, to kind of keep your hands on your grasp what's going on from one, one moment to the other.
Um, so I'll leave it at that. And, um, I would not be surprised if we see even more actions taking place, especially as, as it kind of is a, this part of the strategy of the US to maintain some sort of leadership, or even in there at our view, the country's view with dominance over AI in its escalating war with China. Uh, Robert, this troubles my free market soul because, uh, you know, basically the United States government is putting its finger on who can buy what, when, and where is this gonna become the new normal?
'cause we could apply this to all kinds of tech. Well, absolutely. You know, when, uh, when, when GPUs are outlawed, only outlaws will have GPUs.
Um, you know, it, it's, it, we, we've seen this, you know, concerns about export controls, you know, and it worked out so great with, uh, you know, uh, PGP, uh, you know, restricting, uh, you know, uh, encryption technology. Uh, you can't stop it. Um, also I think it's a bit overblown the impact that these chips have.
Um, you know, look at, you know, we just have to point at deep seek to get an example of being able to provide, um, good enough, uh, AI technology on, uh, not the latest and greatest chips. Uh, you know, I I also think Senator Cotton should have taken a trip to Bentonville and, and talk to a large retailer there to see if they are okay with the GPUs that they're consuming, uh, phoning home. I don't think that they would be on board with that.
And also, any technologist will tell you that canceling phone home technology is super easy over the network. Um, I just don't see this getting out the, the way to, you know, implement something like this. The scale of it is, is simply too big and, and I just don't see this progressing.
I think it's political theater because the Senate's trying to restrict it, but then we have the executive branch trying to do the other thing. In a previous life, I used to cover the channel and the, we had this area in the channel known as the gray market. This is that whole realm of middle people or middle men or women who, uh, sell all this stuff to folks.
'cause of most of what you buy, you don't buy direct for many vendor. And a lot of the vendors turn, uh, you know, a blind eye to where a lot of their goods and services winds up. And that's how come suddenly chips are in China that went through Singapore, and nobody quote unquote, knows how they got there, but they damn well do know how they got there.
So my question to you, John, is, um, is this gonna upend the whole business model for a lot of these companies? It's, we started tracking on a granular level every unit of something should. I was Like, it sounds like a logistical nightmare.
Um, you're right. The this, this chain, which is complicated as it is, it's more complicated now than it's ever been, um, in terms of parts where they're coming from. And then, and then on top of everything else, we have the tariffs, right?
Which, which is, I didn't mention, which is another poli political football involving tech to great extent. So yes, Mike, I think it's, it, it will be an aggravating incredibly, uh, annoying, uh, problem. And I think we're already seeing that.
I think, I believe it was a MD and Nvidia were, were performing write-offs in terms of, uh, fracking their, their chips, uh, through all these various permutations. Um, it's, I don't, I can't even imagine what's gonna happen next. I mean, it's the unpredictability in the, in, in his Robert points out, there's a, that that seeming contradiction between the government, or at least the Senate and the House trying to restrict the, the, the flow or, or, or not trying to restrict, but trying to keep track of the flow while the White House is, is, is cutting deals with other countries.
It's just, it's absolute chaos. And I think the tech industry, of course, I think they're delighted now because in a sense, if you're one of the power brokers or one of the companies with the ear of the president or is administration, you are gonna benefit. We're seeing that already.
Yeah. I'll, and this troubles me deeply on this level, right? So the president wakes up on the wrong side of the bed one morning and suddenly, uh, my access to AI chips is constrained for some reason, because, you know, he is trying to negotiate something else that impacts me as a company.
I mean, how far can this go? I mean, it's one thing, I guess at the country level, but do individual organizations are gonna have to start thinking twice about, you know, who's annoyed at them in dc? I don't think this is gonna go very far.
I, I think it's deliciously naive to believe that the people that are actually making good use of these chips would bewared by these, these lackluster controls. It, it's easily, as Robert said, deactivated, this is something that, that I don't think is, is gonna actually work. I think all it's gonna do is anger people.
Um, I just don't get, it just shows us how little our legislators understand what's going on in tech. It just, it just highlights for us, um, that That's always, you know, like that, that's always been the case, Anne, right? I mean, they just stay fundamentally, Not like watch any Senate hearing.
Right. Watch any Senate hearing with any big tech, CE and you're just like, oh my God, you don't get this. You don't get this.
And so is, if this is the move that just shows me they don't get it, um, because this is not gonna achieve anything. Meanwhile, we're shipping 18,000 Blackwell chips to Saudi Arabia. Woo.
John, you know what interested me as well about all of this? Yeah. Was who wasn't on this trip?
You didn't see, you know, Intel. CEO, you didn't see a Broadcom, CEO. There's a, you know, apple CEO is missing.
What does that tell you? Tells me a lot. I mean, but remember during the, the Biden administration, he was in Ohio with where the plant was gonna be built with Pat Gelsinger.
Remember when Pat Gelsinger was a, was a guest during I think a state of the union speech? He was acknowledged. Um, Broadcom, no sites a MD none.
Yes. Apple seems to be a little bit out of favor. Um, they're having their own problems with the EU and perhaps with the Justice Department.
So, you know, Trump does this. He plays favorites. Maybe eventually we will see Apple in the good graces.
I know we're gonna talk about Apple later, and it's, and it's, uh, in Siri. But I mean, in terms of, in terms of Apple, they got some major problems in terms of Apple intelligence. We can talk about that later.
Um, it's, it's just, again, it's just, it's whoever, whoever has whoever talked to him last, whoever talked to Trump last, maybe Jensen did, maybe Sam Altman did. They were front and center and got the rewards. I think if Byron the reports correct, checked he got some candy out of this too, though.
They got a, a small portion, a small portion of this deal was allocated their way as well. So I'm not sure they were on the trip, but they got something out of it. They weren't there, But yeah, they, they, at least they came away with something.
I, I just, I always feel badly or for Intel, just, it's just such a long, slow decline. And, um, again, they're left on the outside. Mm-hmm.
Robert, what's your best advice to folks then about all this? Should I just ignore all this political machinations and carry on is normal? Or is there something I should be worried about?
Well, it depends on what your goal is. I mean, if your goal is to maintain solid mental health, yes, ignore it all. Uh, you know, if, if, if your goal is to make business decisions, um, then, uh, look, I do believe, um, that, um, access to chips is a bit overblown.
Um, certainly, um, you know, there are, uh, quite a few things that you can do with older chips. In fact, you know, with, with my, uh, uh, RTX 30 80, I'm creating neural networks with, uh, you know, for image classification, just fine. You know, with, with my Lego brick sorter, it's not a problem.
Uh, if you are trying to build a competitor to, uh, chat GPT, okay, you're gonna need a little bit more. But for most of the AI tasks that businesses are going to be working with, um, you're okay. You don't need to go and get the most expensive stuff.
What you do need to do is get some outstanding experts that are gonna focus on tuning that model for the hardware available to you, no matter, um, no amount of export control is going to change efficiency when it comes to software in creating models and tuning them. And, uh, you know, uh, uh, mother is, or I'm, I'm sorry, the, uh, mother of invention is necessity. That's why we saw deep seek.
That's why we're seeing the acceleration of open source, true open source, um, models that are driving value. I think a lot of this stuff is political theater. Um, and for mental health purposes and also for business decisions, I don't think it matters.
And Well said. Yeah. I got one thing here.
In my experience, and looking back in history, every time you attempt to restrict something, you wind up seemingly creating increased illicit demand for So am I gonna see GPU smugglers now? And, you know, people Absolutely. I, I knew people that were smuggling PGP binders and, you know, I used pg p in college.
Yeah, I remember. That was the thing people did. And they were like, I'm gonna tattoo it, and then they can't tell me I can't travel with it.
It's just, you know, don't, don't sweat the small stuff. Right. And, and when you do, you make it a bigger thing.
It's, and by the way, we still don't know how deep what chips deep seek was developed on. There were rumors that they had snuck in better AI chips. Mm-hmm.
But, but that was never substantiated. There's no proof to suggest that deep seek required all that work required these amazing chip sets. So we're also just sort of assuming this is a hardware race, when really it's not, it's not that simple.
Mm-hmm. And I'm reminded of those days when, you know, I was in college and the house would get robbed and the stereo would be gone. And now if you get robbed, the GPUs are gonna be stolen.
Right. Catalytic converter GPUs. Yeah.
Yeah. Yeah. Just the idea of restricting all this, I if you think that this is a good idea, then just hang out with, um, you know, your, your average middle school students and ask them how they get access to vapes.
Uh, I I think if 12, 13, 14 year olds can get access to that, um, we're not gonna stop this. I, I do wish they would apply this technology, phone, home technology to, um, uh, prescription opiates, uh, that, that I think would've had more positive impact to the country. Uh, but, you know, who knows if they wanna restrict, uh, GPUs?
Great. And It also given, well, yeah. The TikTok ban.
Look how well that worked. Yeah. I was gonna say, given the ineptitude of the, of the federal government, that these, these, these bills are probably not gonna go anywhere against the lobbying of big tech, especially Nvidia, which seems to have the year of the administration and everyone else.
I don't think it's ever gonna transpire. Right. I won't tell you one thing that will happen for sure, though.
There'll be more GPU hoarding than ever. And people are just gonna go out and buy these things and shove 'em in a closet just in case. 'cause nobody knows what's going on.
And that's been going on for a while. A lot of these GPUs organizations are buying, and they're not actually using it because they're like, well, we never know, but at least we get 'em. What?
We got 'em. Hey, Well, I cannot wait for the inevitable Beanie Baby, like, crash for GPUs. That will be wonderful.
Mm-hmm. True. Oh my God.
Those are called AI accelerators. And they'll be available in a store near you. One minute.
I, I can't wait to, to run my old crappy games at the highest GPU settings. Can't wait. All Right.
Awesome. All right. We're clearly not taking this too seriously, but folks, keep an eye out 'cause Well, you never know what'll happen.
We'll be back in the middle. All right, folks, we're back. And we're talking about Pope Leo the IV for newly concentrated, and one of the first things he said was that AI for ethical use is a good thing and that we should investigate more of this and maybe apply it more broadly.
Um, first thing that comes to mind, of course, me a former Alta boy, I'm like, well, you know, that pre shortage might be a lot less if everybody just used ai. So who knows, maybe we'll have an AI sermon and a delivery and I don't know, maybe you go to confessional and does it count if you confess your sins to an ai? I don't know.
But John, what's your take on what's going on here? Will this become the new norm in other religions as well? Uh, I can't speak for other religions, but I, I think in terms of the Catholic church, um, this has been discussed.
It's been a topic, it's been gaining traction the last couple of years. I remember doing a story here for digital CXO, uh, when the late Pope Francis, um, talked about the same type of framework. He said that while technology contained a potential to serve humanity must be used ethically.
And he talked specifically about how the inherent risks of AI and other things must be mitigated. I also remember, I believe it was in 2024, he addressed a G seven session in Italy on the subject. And he, he followed up with a speech, um, at the Vatican on, on something called generative artificial intelligence and technocratic paradigm.
Um, there was also a, a study done between the church and Santa Clara University. I, I wanna say it's a couple of years ago in which they came out with a pamphlet and talking points about the technology. So they are ser they are taking it seriously to a certain extent.
And I think it's kind of a continuation. What Leo is doing is a continuation with what Francis did in terms of kind of, i i talking about things that are, that are not these old age old institutions. I mean, they're talking about current events, whether it is technology or whether it's political or cultural, and they're kind of entering the, the current world versus the kind of old state approach.
So I think it's, I think it's encouraging and perhaps maybe other, uh, religions will follow suit, who knows. But, um, there's a continuation of what Francis had had started in kind of kicks, kickstarted the last couple years. Mm-hmm.
And is this just another form of AI therapy we've seen that kind of evolve over the last couple of years, and it's being more widely used, and you could argue that religion is a spiritual experience and much like therapy can be. So is this kind on the same continuum? Yes.
I, I would say to some degree I think that, you know, this is a new Pope. He is trying to relate to people. He is letting us know who he is.
Um, I actually recently had a friend confide in me that she had been using chat GBT for therapy. Uh, because she said it, it didn't feel like it judged her. Uh, also FY she's Catholic.
So coincidence, I don't know. Uh, I told her, you know, you could tell me anything. You don't have to rely on Chachi, BT we're old friends.
But anyway. So I, I do agree that this is just, you know, maybe he sees it as a way to uphold spiritual principles. Maybe it's a continuation.
Um, maybe you, you know, the leap of faith you take to be religious is, is akin to the leap of faith you take to seeing AI as a meaningful thing in your life? I don't know. Uh, for me it's a logic driven decision, not, not a faithful one.
So I, I don't know. But I think, I think it's just him letting us know who he is. I think that it's the church playing global discourse in a conversation.
There's over, I think, a billion Catholics in the world. Um, and it's a green light. It's a green light to say, this is okay.
Um, and hey, go, go have fun with this. And maybe it can help engage people in the church in a different way. I mean, that could be interesting.
Mm-hmm. And if it helps people, why not? Why not?
There's a shortage of therapists. People can't afford them. You know, if it makes you feel better, do it.
No. Why not, Robert? Do I have to worry about a deep fake taking over Pope Leo the 14th here and kind of fooling everybody into doing something they shouldn't be doing?
Um, I, I, I doubt that. Uh, look, the, the, the real po the, the real purpose I, I think of, of what he was talking about, his hope was to, um, start, continue that conversation about ethics and ai, um, and, and how we, uh, use these new tools. Uh, it, look, Catholic Church has been around for a while.
They've seen quite a few ways of technology. And, and this is nothing new about, uh, uh, focusing on, you know, uh, dignity and, and, and justice. You know, this, this is always a push for, for all religions.
Um, you know, I, I do think that there is an opportunity for companies like O Open ai, which is a B Corp, which was set up to really do research, uh, and exploration of, you know, ethics in ai. That was the hope and drain. And, uh, we're really not seeing that there.
There's a big rush into, uh, what we can do with AI and, and pushing the boundaries for this. And, and I'm reminded of, you know, a, a line from Jurassic Park where, you know, we were so focused on if we could do it, we didn't question whether we should. And I do believe that focusing on is, you know, how are these models going to affect the lives of people?
Uh, are we going to start using AI to make decisions that impact people's lives? Um, college admission, uh, uh, you know, credit worthiness, those sorts of things. Uh, um, what about if it starts creeping into our, uh, legal system and criminal justice system, uh, is that gonna impact sentencing and those sorts of things?
Uh, we need to be very careful of these things. And I think that that is what, um, the Pope was bringing up, that there is an impact on individuals with ai. If we just blindly say we were gonna turn over decision making to the model.
Yeah, I think they're trying, they're, they're, they're trying to get ahead of, of what AI can do, both good and bad. And I mean, I think that's what the government's trying to do, too. I mean, it's the one technology where people are fully engaged.
It's the one technology I, I've experienced or covered where everyone seems to have an opinion. And I think right now what they're trying to do is position us to think more about the repercussions of what, what it can do and what it can do to us. Yeah.
I mean, it could get a little outta control, right? So suddenly you're referring to an AI agent as a father, and then maybe ultimately it gets promoted to Monsignor, and before long it's a bishop and a cardinal, and it's electing the next pop. So how far do you want to go?
I do believe this is how, that's the beginning of Terminator, right? Uh, that, that's how it started. I, I don't know, it's been a while since I've seen it.
It, I dunno. Mm-hmm. I guess, yeah.
I, I think they'll have to put a clause in there that says, you must be a, a an actual breathing human to like the next pop. And I'm sure somebody will get around to amending whatever the rules are. But I mean, don't, don't you think that a lot of the things that are being said about AI now, like, oh, it's gonna destroy your ability to think and oh, it's gonna make us dumber.
Weren't those same things said about the internet, about television, about radio? I mean, how far are you gonna go back the, these sort of naysayer comments don't really feel new to me. It's true.
You know, people bemoan the fact that our kids can't read analog clocks, and they look at us and go, well, who cares? I, I got the time on my phone. So, you know, we Hand a map, hand a paper, yeah.
Hand a paper map to someone, to a genzer and see what happens. Yeah. Right?
Mm-hmm. And is that a bad thing? Is it a bad thing that, that they, you know, have tools that are faster?
I don't know. Um, unless you're a survivalist, is it really something that's gonna come to play? I don't know.
I think it, where it, it concerns me is the lack of critical thinking. If we're outsourcing our thinking, you know, do we not get dumber? I don't know.
Or do we get smarter because we're not spending our time on repetitive processes? I'm hoping, I dunno. But hoping, I'm hoping for the latter.
Because, you know, at the end of the day, a lot of the rote stuff that we all do tires you out. We are humans and we spend, I'm hoping that we're gonna spend more time on the things that matter versus, yeah. I don't Know.
That's loading Story, loading stories. That's Whole point of ai, right? Is to, the whole point of AI in AI agents is to move away from road tasks and be more of a critical thinker, or be, or somebody who thinks kind of outside the box.
I mean, that's the purpose. We'll see if that at leads to that. I'm hopeful.
I don't think outside the box because there is no box. I don't recognize any box that limits me. Oh, I like that.
And rejects the concept of a box. I like it. Wow.
No box brand. Yeah. No, no.
I am not imaginary. No imaginary constraints for me. I am a free thinker.
Um, I will say I have hired recently, and anyone who has hired in the last six months is getting a flood of AI cover letters. And so I didn't require a cover letter. Okay.
And so I get these cover letters, and there's all the telltale signs, m dashes, overly flowery language. Oh, here's a couple specifics sprinkled in. So you think a human wrote this?
And so I asked people, I said, today I write this. And alarmingly like, people denied it, people denied it, and the one that didn't, and said, yeah, of course I did. I thought it was a, a better use of my time than, than writing a cover letter.
And I wanted to stand out. That person went to the next round because I appreciated that they were honest about it. I don't mind if you use ai if you're saving time.
I just mind the, the deception. Mm-hmm. All right.
Well, I'm not quite clear exactly how all this is gonna play out from a religious perspective, but I would say that the more time we have to ponder maybe the right and the wrong of things, the better humans will all be. How about that? Amen.
All right. Bless you, my son. All right.
And, and, and we'll be back with the next reading of the gospel in a minute. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right.
Well, we're gonna shift gears a little bit, but you could argue that what Apple has been up to is now officially a sin. But, um, they are now determining how much cash to hand out for folks that, uh, apple got busted for eavesdropping with Syria on folks. And they're not the only tech company that's been having this issue.
But, and let's start with you. Are we gonna see more and more of these kind of payouts for violating people's privacies? Because it seems to me that this is rampant.
Well, we're used to seeing it in the eu, right? But we're not as used to seeing it in the states. I think that someone somewhere calculated on a spreadsheet, we could keep fighting this, or we just pay it out.
And this is, this is chump change to them. $95 million to one of the richest companies in the world isn't really much. So they settled that, uh, class action lawsuit because Surrey inadvertently recorded users private conversations, which I think we all knew was, was happening.
And it claimed that Surrey sometimes activated unintentionally and captured sensitive discussions, uh, that were later reviewed by third parties. It was a very ominous sort of, uh, email that I got, and anyone with an Apple account got yesterday. Um, I would say that the $20 payout is probably not worth my time to go and pursue and prove.
Um, but I do think that it was interesting because the same day news broke that they are working on a brain computer interface. Uh, they wanna control phones from their brains. I was more interested in that than the lawsuit.
Uh, and then I was thinking, wow, that future lawsuit for, that the brain computer interface is gonna, is gonna just blow this out of the water. Um, but I do think that they managed to not really cop to what happened. The language was very vague.
And I think that it was just a write off. I think it was a write off to move on and go back to business as usual. I doubt anything will change.
Uh, apple is viewed as the white knight in this, in, in this, uh, privacy battle for a lot of reasons because they've marketed as such. But this shows us that they're just like everybody else. Mm-hmm.
Robert, is it me or am I getting paranoid? But every time I turn around, I seem to feel like I'm talking about something with my wife or whoever, and then suddenly on some device website or whatever, I'm being treated to something that is almost spot on that topic. Um, well, it could be you are being spied upon, or this is confirmation bias.
Uh, it, one of the, it could be either one. It could be both. Uh, I have no idea.
I will say this. 75, uh, million devices. Um, that's not a lot.
Uh, it's, it's the, this, you know, uh, you can do five devices and get a hundred bucks. Hmm. Okay.
I think I could fill out a form for a hundred bucks and I absolutely have more than five Apple devices, but also 95 million for a treasure trove of data of voice. Uh, what a bargain. What a bargain.
Uh, and, and, and you know, it, this reminds me of certainly the, um, Google went through this where they were, um, uh, capturing with maps, uh, when they were getting all of the street view data. They were capturing a bunch of wifi information and they said, oops, my bad. We're, we're, we didn't mean to do that.
Uh, but really didn't get a lot of clarity on what they did with the data afterwards. Um, and, and so time and time again, people will, again, you know, these companies say how much, you know, and very insightful. It it, how much does this cost?
What, what's the, what's the ROI on this? Oh, we're coming out ahead. Great.
This is cost of doing business. Um, and uh, I don't see this as really much more than, um, okay, let's make this go away. I don't see this really significantly changing corporation's behaviors on how they do this.
Uh, a lot of this stuff seems to be, um, it's better to ask for forgiveness than permission. John, is anybody talking about this in the valley? Is this a concern or is this kind of just you?
Um, it, it, it kind of unders, yeah. I mean, it kind of underscores two things about Apple. Um, but one, as you said, it's the white.
I think Ann said it's the white knight in this whole battle of her privacy. Well, the Dark Knight is obviously meta, but I think it brings up two things. First, there's that little $95 million, by the way, is nothing to Apple slap on the wrist less than that three over $3 trillion they have.
Exactly. Right. I mean, nothing, it's a nice investment, actually.
But what it kind of brings up to me is the, the one story we, we hear about Siri and about anything AI related with Apple has got this little kind of minor negative tinge to it. At the same time, we're reading about everybody else hurdling ahead of Apple in the AI race. And I, this, I kind of, I wanted to bring this up because I've talked to at least three people in the last couple of weeks, and who used to work for Apple, they used to work within the Apple intelligence arm of things.
And they all told me they resigned because mainly out of frustration in this idea that Apple's pretty much, it's pretty much an aimless flawed project. I think even Warren Buffet has, has mentioned his, his, his mis his his misgivings about innovation in Apple at this current state. And I think it just kind of re it's, to me and to people out here, it's kind of a reminder of Apple, kind of, kind of fumbling its way around AI so far.
I mean, I'm not saying they're gonna fail, but there is a genuine concern, especially among the ex-employees who just left with throwing their hands up. I would tell you what I would like to see though, is instead of you sending me an email that says I qualify for 20 bucks, can I just check a box that says that give my 20 bucks to some charity somewhere, then we can all set up. 'cause 95 million to a particular charity could make a big difference.
Is that legal feasible, Or It's a good Question. Make sure, sure. People could set up a GoFundMe and then give 10% of that to GoFundMe.
But, um, which is why I don't, I don't like those. So, And what happens to the 95 million if only 30% of the people actually go bother to claim their 20 to a hundred bucks or whatever it is? I don't know that it's all gonna get claimed because it's a little tedious for 20 bucks.
Right? Right. Um, I'm not gonna do it, you know, So does our, Our primer.
Yeah. It, it will, you know, they're off that top of that. The, the settlement amount, uh, for the attorneys that did did the class action, they're gonna get their fee that's been negotiated and the, um, the rest of the money goes through a clearing house.
If it is not accepted at a certain point, it is returned to Apple. Wow. So, so maybe, Maybe we should do it just to, How much should we spend that, you know, this 95 million actually shows up in the people who were allegedly victimized maybe 10%.
Right. Look, I'm, I'm gonna do it for a hundred bucks. I mean, and it's gonna take me five minutes.
I would forego all of the money and just to know what the third party was that got it. And what did they do with it. That, that's more interesting to me than $20.
I, I wanna know what, where it went, because it's very ominous in the language. It just says a mystery third party. Well, that's, yeah, that's not the deal.
And if you wanna find out, don't take the payout and hire a lawyer. Oh my God. Well, you know, we see these kind of arrangements all the time, right?
So maybe, I don't know, can I create an AI agent someday that will manage all my claims that I'm allegedly qualified for? And, you know, I add 'em all up 20 bucks, it turns into real money over time. So maybe there's a way to manage this so that it's not so tedious and you can have the AI agent direct that money to whatever charity you want.
Let's do that. Yeah. I mean, I, I do think that the legal industry is one where a AI stands to disrupt quite heavily.
You know, you've got a lot of old case law to go through. You've got, I mean, and you've seen cases already where people are getting busted, making court decisions and writing legal briefs using ai. Um, and I think that's only gonna continue.
Well, ultimately, we could have probably come to the conclusion that 95 million was the number to settle for if we just used a little AI about last year, right? Yeah, absolutely. I mean, it sounds good in theory, but then I think, okay, five years ago, blockchain was gonna replace lawyers too.
Remember that we're gonna use contracts, uh, on the blockchain and, and buy houses and cars and Yeah. Where's that going? I, I, I think we'll just file more complex court cases and, and the routine stuff will be handled by an ai, hopefully, and we, maybe we can clear up some of those, uh, backlogs and court cases that are holding up the legal system.
Uh, so, you know, theoretically it could work and this would just be yet another example of a case that could probably be litigated in an hour, rather than taking how many years to settle this stick. It's a little crazy, right. John, what's your prediction here?
Is this a one-off, or are we gonna see more of these Suits? Let's see. More of these probably, but, uh, you know, if they continue at this, uh, this rate, 95 million is well worth the investment to kind of, uh, you know, collect data, it's well worth it.
Mm-hmm. And Robert, do I need some sort of way to track what people are doing with my data if they get it, no matter how, whether it's illegally or legally, but seems like we don't know where our data goes. Uh, you're right.
Uh, we don't, and, and that is gonna be a challenge. Um, there are certainly a large number of companies that are looking at how people can protect their data and their privacy. Um, and companies are certainly looking at how they develop their privacy policies and how they manage that.
Um, you're going to see an increase, um, in consumers being concerned about it. So whether that is hardware manufacturers creating devices that are secure and hold data close to you and, um, on the edge, uh, perhaps, uh, but you are gonna see more and more people, uh, especially, um, educated, you know, more advanced users, like the people that are watching this and, and that are speaking here, are gonna be interested in this. Um, however, I don't think that there is a big backlash amongst general population on this stuff.
Uh, you just simply look at the rise of social media and remember kids, when the product is free, you are the product. Mm-hmm. And so people have been giving away their data for years.
So there is a large population that doesn't care. Um, there is a growing and significant population that does care. So I do think that you're gonna see people that are concerned about it.
Um, look, everybody should be concerned about data privacy and their data. Uh, but I don't think everybody is. Mm.
So lemme ask one more obscure question, but John, if I go infection and I'm using an AI priest, is that AI priest sworn to secrecy like a regular priest, or can they be called to testify against, He's gonna share it, is gonna share it's data with a third party? That's unknown. I'm being facetious, so I I have no idea.
I mean, that's, that's this, the, the whole problem is, is Robert was pointing out, and that's something that Facebook, we always leaned into, uh, this, this, you are the product, and I think there is a TA tested trade off for most people. Most people are willing to accept that. So they're willing to accept the risk, the, the broad audience, and there are going to be those who will, who will not.
But for the most part, the vast majority of people are willing to take that risk and it'll happen. Right? I think people generally that I've spoken to about it are like, well, I'm not doing anything wrong.
What do I care? You know, and, and apathy is really the enemy here, but I'm less interested in what Apple's doing with Surrey data, which by the way, I assume they were doing, uh, than I am with the FTC case. Uh, and the DOJ plan for Google, uh, the antitrust case, I've been following that very closely.
And yesterday the FTC came out backing the DOJ to force Google to share search data with competitors. I mean, whoa, that data, your search data that getting let loose to other companies is that, is like a way bigger ramification to me than like whatever weird things we've all said to Sury. Uh, Robert, I'm thinking the next thing thing in home real estate is gonna be soundproof rooms where you can go in there and you, I abs absolutely, uh, uh, Faraday cages, uh, for private conversations, uh, the, the new, remember we had the conversation nooks, uh, in the seventies, the sunken living rooms.
We're gonna have Faraday cages now, uh, uh, in our, in our, our houses. Um, for, for the, the really hip people have those. Um, I mean, I am concerned about, uh, Google sharing my search history and that getting out because, um, I am a terrible software engineer.
And the questions that I have asked, um, Google on how to solve a very simple and easy and chucklehead problems, oh, I'd be so embarrassed if that got out and everybody realized what a horrible software engineer I am. Uh, I mean, that'd be terrifi. What about all of us that use go to Dr.
Google? I'm not worried about that. I'm, I'm just, my pride, my pride about like pride.
I get it. I, you had to Google that, you idiot. That's what I'm worried about.
I mean, if that all that gets released, I think we're all in for some embarrassment. I don't think you're alone in that. Well, doc, according to Dr.
Google, I should have died three times in the last five years. So I'm not so clear that that's really something to lean on too hard. But, um, fortunately we have AI search now, right?
So you just kind of plug it in and nobody will know exactly what you're looking for anyway. 'cause the AI will know what you're looking for. And so you can just get all that code that you're supposed to know how to run for free.
Are we gonna use search? I don't think so. I think we're just gonna talk to our machines and then the AI will tell us what we wanna know.
The problem is, it'll never forget what you asked, right? All right folks, we're gonna leave in here. Thanks for watching everybody.
I wanna thank our guests for sharing their knowledge and insights. As always, we're gonna have an awesome lineup of Techstrong TV coming up right after this. And we'll see you guys next time.
Hey everyone, welcome back here to Techstrong tv. You know, I'm really happy to have our next guest on here. He hasn't been on Techstrong tv.
We were talking nine, 10 years perhaps. com, March of 2014 was our first publication. And, uh, those first two years, I mean, when you talk DevOps, it was all chef and Puppet, maybe a little Lance, bill and Jenkins.
And, and Julian was a key, key person at Chef, and he'd always come on and keep us informed of what was happening there. I want to introduce you to Julian Dunn, senior director, product management at Chain Guard. Julian, it's a pleasure to see you.
Yeah, it's great to see you too, Alan. It's been a while. Well, You haven't changed a bit.
I've gotten a little Older. Just a little inside joke. We were talking off camera.
So Julian, I mentioned you were at Chef, but you know, for people who aren't familiar with Julian Dunn's, uh, life story here, give us a sense of your journey. Yeah, well, as you say, Alan, we got to know each other at Chef. And, you know, prior to that I was a DevOps engineer and a software developer.
Um, but I moved into product management at Chef, and then I took a little bit of a detour too, uh, at Chef. And then from there I went to PagerDuty and did some product marketing for them, uh, for a couple of years. Helped to take them IPO and PagerDuty, also a great company, also very, very adjacent to the DevOps, uh, category.
Uh, sure. Then I had an incredible opportunity to move to GitHub and help them to, uh, scale the GitHub actions product. And I was there for about two and a half years.
And as you folks know, in the DevOps community, you know, GitHub actions is, and nowadays it's sort of your predominant CICD, uh, platform. A lot of developers use for that and for, uh, automation. And then I had the opportunity to come here to Chain Guard, which is a little bit different, but it's still adjacent to DevOps.
Um, but, you know, chain Guard is in the, the cybersecurity space. And if you're not familiar with chain guard, uh, chain guard basically is the safe source for open source. Um, we make, uh, well, our first product was, uh, container images that were, uh, low to zero vulnerabilities.
'cause you know, a lot of the containers that you actually download out there have hundreds of vulnerabilities on day one, the ones that you get off the internet. And we thought, how can we actually fix this? This is actually not a good way, um, for developers to start building things.
Um, and so it actually turned out to be really hard, but I love hard problems. Uh, and so I, I wanted to join a company that was solving those hard problems and bring real value, uh, to, to developers and DevOps engineers and, and platform engineers. data if you're not familiar with us.
Absolutely. You know, I became aware of chain guard, I'm going to say four or five years ago maybe. 'cause it really, you know, I, I as Cube Con, so four or five years were coming, you know, towards the end of COVID, let's call it.
And, um, you know, all of a sudden this company was like secretariat coming around the, the, the, the curve there for the Belmont Stakes. It started coming on strong. Everybody was talking about it in, in at CubeCon and, and, and, you know, a lot of cloud native, uh, events.
And so, you know, part of what my job here is, is, hey, you got to be aware of these things. And it's a great story. Of course, you guys, I think announced, was it, was it CubeCon, uh, Europe in London, a a a a huge round?
Or was it maybe subsequent to that you guys recently had a large fundraising round announced as well, right? We did. We, we raised a series D and that was just announced recently.
Um, and that's hot on the guilds of the Series C that we raised last year. Yep. So things are really happening there.
Um, actually we're here today 'cause you got a bunch of news you're gonna share with us, Julian. That's right. I do.
We had our inaugural conference, uh, chain Guard assemble. And that was a couple months ago. Um, and as I, as I mentioned, when I first joined the company, we had one product and that was chain guard containers.
Um, but we, you know, what it takes to, like I said, the problem set is really, really hard to go and solve. To make those zero vulnerability zero CBE containers means that we had to build a whole set of automation, what we call a factory under the hood that continuously monitors a lot of different open source projects out there, figures out which ones need to be rebuilt, rebuilt all the ones on top of it that depend on that one, and basically ship those containers to customers very, very quickly within the, you know, within seven days, there's a critical security vulnerability that's, that's, um, that's found. And then one of the things that, or several of the things our customers said to us is they started adopting these containers was, well, now that you have this automation, is there anything else you could apply this to?
Look, we have a set of problems over in our, you know, application libraries. These are, for example, in the Java ecosystem. These would be your jars, um, that, that are used as, as dependencies for your Java software or in the Python world.
These are your wheels that you use under your Python code. Is there anything you folks can do to build a product around this? And we looked into it and said, yes, we could, we can use that automation in the factory to, to move up the stack towards developers and help developers be able to reduce, um, security vulnerabilities.
Um, now, uh, in the libraries world, the vulnerabilities happen in a different sort of layer, which is at the build and distribution points of libraries. You go back in the history, you sort of like look at the history of where attacks are coming out. And by the way, you know, you just, you can just pay attention to the news every week.
Alan, I'm sure you touch on this too, but just like every week it seems like there's a security vulnerability in this area, libraries and nine times outta 10 or more frequently and spokes that are trying to attack Maven Central pi, PI N-P-M-J-S, these distribution points, or they're trying to attack my old stopping ground, the GitHub action and try to compromise that workflow so that malicious content is being uploaded to those distribution points. That's a lot easier for attackers to go after than to actually break into GitHub itself, that source code. Uh, because you know, these, those, those platforms, the, the phis and the Mavens of the world or Maven Centrals of the world are set up for kind, kind of like the creator economy makes it really easy for folks to, to share and to upload new content there, right?
So you get typo squatting attacks and things like this. So what we're doing in Chain Guard libraries is, hey, if the source code is what's hardest to break into, why don't we go back and try to find the source, coordinate for all the top the popular libraries going back a few years, and try to build those from source in the same factory that we have for container images and then offer those in a secure offering to our folks, to our customers. And we've gotten a lot of, um, a lot of interest from enterprises, fortune 500 companies, you know, folks are looking at this and being like, my, the risk surface here is, is too high for me.
I really love that solution, um, of, of, of chain guard libraries. And then the other announcement that we made, Alan was also, you know, folks saying, Hey, you know, I still have a lot of virtual machines in my estate in the predominant use case for virtual machines vis-a-vis chain guard. Well, containers have to run somewhere.
They're just not uploaded magic to the cloud. They're still executing on some, some machine more often than not, that's some kind of virtual machine or what you might call a container host up there, right? It runs container D and a bunch of other services and things like that.
And we thought, what would it take for us to extend, but we already kind of know as chain guard os if you will, and extend it to be able to, to, to meet a, a virtual machine use case. So what would that take? It would require us to build a kernel.
It would require us to build system D and a few other services and container D and these cloud agents and things like this all from source and then ship, ship customer of that virtual machine image that they can plug directly into either a hosted, um, Kubernetes service, like an ela, uh, EKS and Amazon Elastic Kubernetes service, or maybe in their own Kubernetes clusters where they're bringing their own container hosts. So we announced that as well at at chain guard assemble. You kind of think of that as almost like going the opposite direction in this pyramid in the stack, right?
I'm going down the stack more towards the bare metal. So we, we think we we're trying to protect the supply chain software supply chain at all levels of the stack. Um, and so we think, you know, with this, with, with these two announcements, it's a robust platform that we now have to go and do that for customers.
So before we go into maybe more announcements, let's, let's hit these two in terms of libraries. You know, I, I recently, I was at RSA conference, I don't even remember, was it two weeks ago or a week? It was two weeks Ago.
I was there Two hours, yeah, two weeks. Yeah. Where are you at?
You shouldn't come by and said hello. We, we did our DevSecOps thing that we always do, 10 year, 10th year anniversary of it on Monday at, at the Moscone Center, and then I was at, uh, broadcast alley all week, but I was talking to the folks from Sona type, you talked about Maven and everything. You know, they've come out now I call it a firewall that sits in front of the repos.
And so when you are downloading from the libraries components or what have you, it's actually checking, is it really the what you think it is? Is it compromised? Is it, is it an old version or a new version?
And there are some people who for whatever reason need to use an old version, but you gotta be aware of, you know, the, the exposure there. And to me, this, this was Julian, this makes so much sense, right? I I had almost put the onus on every repo library kind of source that, hey, you, you have a duty to put a border control, right?
Uh, border controls are a big thing in this world today. God knows, I don't want to go there, but, you know, we should have them at repo certainly and, and be doing something about that. How does libraries play into that at chain guard?
And then we'll come back to the vm. Yeah, I think, you know, one of the thing things is that, you know, those types of firewalls are useful in, in some ways for signaling to folks. What are the risk levels?
You know, they're using sort of heuristic analysis. You, as you pointed out, there's some type, there's a few other products out there as well. They're sort of trying to grade things or whatever and use heuristic or sometimes even AI or ML analysis of, of projects and things like that, you know, they are helpful to a certain extent.
Um, what I would say is that, you know, there's a, just the flood of how the, the volume of how libraries versions change. New things are published all the time. Sometimes things become malicious over time.
It's not like the library itself that that author was, was doing anything malicious, but somebody, some, sometimes nation state actor is realizing the popularity of some library and then without that author even knowing is going and doing and, and kind of perverting it and changing that library and creating new versions that don't exist and uploading them to these repository systems, right? Um, so the firewall is one line of defense against that. But another line of defense is let's just go back to that source code again and, and just build it directly from the source code and what the intent of that actual author was.
And then you can avoid some of these attacks. You can avoid these mystery versions that don't exist out there that that author never created, because you're never consulting a system in which they publish, right? You're just, you're, you're, you're sort of bypassing that.
However libraries does plug into these systems that, you know, for, for grading, for, for rating, because we have all the build information and the provenance and things like that of what we've done and our build system that can be helpful for folks, you know, using these types of, um, policy and curation as well. Absolutely. Let's talk VMs now a second.
Look, it's no secret, right? Broadcom tripled the price of the licensing on some, uh, VMware and right, wrong or indifferent, it's given people pause to evaluate, do I wanna stay on-prem running my own VMware? Do I wanna finally make a move to a cloud, maybe use their virtual machines?
Do I just run or wanna run co you know, a Kubernetes kinda on bare metal system, if you will? Yeah. Um, or, or some combination thereof.
Is that driving any of this chain guard VM That is not primarily, I mean, we're, I'm aware obviously of that macro environment, and I think it's helpful as folks move to the cloud. Uh, it's helpful to, to products that are targeting VM workloads. It's not really, uh, what, what drove this move?
This move, again, I would say was driven by customers saying, look, I still have all these problems with trying to patch my, you know, virtual machine environments. I have, uh, perhaps compliance regulations in my virtual machine environments. You know, I, I don't necessarily have, if I try to solve these problems, sometimes I don't have portable solutions across clouds.
Most customers are multi-cloud today. I mean, sure they have a predominant cloud in most cases. They have an incumbent cloud, but many of them are running specialized workloads in other clouds.
They're looking kind of for one vendor that can help them to maintain virtual machines with very low or zero vulnerabilities, but can also keep current with the necessary software as they're doing virtual machine workloads. So this is like the kernel and container D and all these sorts of things. Um, so that was the main motivation to try to get into, to get into this market.
Right. All right. So Julian, we covered some announcements at your recent, uh, as you mentioned, first ever user event like that.
Bring us up to the minute. What else, what else you got for us? Yeah, we're announcing this is really exciting, Alan, today.
So, uh, as I mentioned at Assemble, we announced sh guard libraries just for the Java ecosystem, and today we're announcing shard libraries for the Python ecosystem. Very and very, very similar value proposition. Same thing.
We're building Python code from source, which looks a lot different than Java, right? It's an interpreted language. So what does that mean?
Mm-hmm. The building is slightly different, right? It's more like packaging stuff into these wheels that, that get installed by pip.
Um, but we, what we found in the service of doing this, we found there's also some, and we'll be publishing some more blog posts about some of this material in the coming weeks. One of the things we found, um, in the Python world, uh, with libraries is there's a lot of, uh, folks out there that don't realize there's a lot of, uh, C code and things like this that's actually bundled into Python. And a lot of that C code is untraceable.
Nobody knows what the source of that is. Or cus or a lot of folks that are building and uploading these things to the pi pies of the world are bundling a lot of, uh, just sort of like, uh, you know, vendor libraries is what we call right shared objects and putting them in their, their libraries. And that stuff is untraced and you don't necessarily know what the code path of some of that stuff is and whether or not the, the Python code is actually calling into to that stuff.
And so, you know, by building everything from source, including these sort of like embedded shared objects of the C code, we are providing full traceability over the Python code that's running in your world, including any of these, what we call native libraries. So I think this is a really exciting, um, announcement process. As you know, Alan Python obviously is used predominantly in the AI world.
You know, I, I have a personal fear that a lot of folks are kinda rushing to market. Would AI products and sort of like security is an after No. You think so?
Yeah. Well, you know the way, but the way to fix this, Alan, is for folks that just start left, right, you have to make it easy for folks to start on something good if you try to add security later on after the horse has already left the barn, it's pretty hard to go and do that. Right?
That's why scanning alone doesn't solve your problems. And so it's really important for us to bring an offering like this to market, to get folks to start good so that down the road when they're worrying about these things, right, they're secured, they're already on something that's good, right? It's zero friction.
How we've kind of like made these libraries work zero friction to developers and doesn't change the developer workflow at all. We're providing just higher quality substitute libraries for developers to use that are built in our hardened factory environment. And they don't notice a thing when they go and adopt this product.
That is important. You know? And unfortunately, Julian, it's an old story with security.
Mm-hmm. We sort of bolted on after the fact instead of built in from the get go. Um, but, you know, but things psy and things do change.
And, and this is a great way of, of getting ahead of it because I've never met a developer who says, you know, I'd really like to develop some low quality code. Exactly. They all, they all wanna develop quality and to have security.
It's just a question of the friction, as you mentioned. Yep. What else you got for us?
Um, well, we also have a couple other features that we announced at, uh, chain Guard assembled that are related to the container. Um, the container product that I didn't mention, you know, one of which is, again, these are all based on sort of customer requests and demand. You know, one of them is customers ask us in the container world, um, is there more that you can do to help us to customize the images that you're giving to us?
You know, and, and sort of, uh, it started with the, I would say the bulk of the request from customers are very much around, Hey, I already purchased a couple of images from you, but we're not told microservice oriented yet, so I need to stick a couple of different images together. You know, I have a workload that's maybe like go and node js or something. Well, I already own those two images, is a way that I can kind of compose 'em together.
I call it like the mix tape of images. And we said, yeah, absolutely. We can build the service for you to go and do that.
And we call that custom assembly. Um, and that's something that we have, you know, on the truck today. Customers can use it.
Um, and in the future we're gonna be expanding that to other different types of customization that, that folks are asking us to do, um, for their container images. And that just eases the burden for those platform teams who are trying to fan out, um, and, and have these images widely adopted by, by customers inside, inside the organization. And another thing that we announced at Assemble and which is really interesting, um, and it's also a function of how we're able to do this feature, um, is because we own the spectrum, we control these different components and the dependencies and, and, and things like that.
There's a feature called what, uh, what we call EOL Grace period. And you know, there's a lot of companies that can't move quite as quickly, um, to upgrade everything in time for when software goes EOL and things like this. And we thought, you know, could we extend some of the, uh, coverage in terms of like low vol, lower zero vulnerabilities for some of the stuff we already built, um, to stuff that's going EOL or maybe has already gone EOL.
So we thought, hey, we can't do anything. If the main package, let's say that's engine X or something, if that goes end of life and, and that primary package accumulates some security vulnerabilities, there's not a lot we can do because that maintainer has moved on, decided they're not gonna maintain that anymore. But if there's vulnerabilities that we can fix from its dependencies under the hood, if we can manipulate the dependency tree and we can bring some of the vulnerabilities, we can eliminate the vulnerabilities that are under the hood by bumping to new versions and assuming that top the package like Nginx still compiles, then we have successfully kept that image at a zero, at zero vulnerabilities.
And so folks can continue to use that. Now, of course, they're still taking on the operational risk of running something that's end of life, but it just gives them an extra, extra, extra little bump. It's what we call it a grace period for them to get to buy themselves a little time to get off that old version while still maintaining a good security posture.
I love it, Julia, for people who wanna stay up on not just chain guard technology, but all that's going on. 'cause you guys certainly have a lot going on. dev?
We have a blog there. Um, and it's got product announcements, it's got engineering announcements and things like that. I did also wanna mention, you know, chain Guard does have a starter image tier.
So we do provide, you know, somewhere in the neighborhood of 50 to 60 of our images, the latest versions of them. So it's a rolling version plus that you can experience the value of Chain Guard and the value of the zero vulnerabilities and the S bonds and the attestations, all that for free. Um, and then if you want older versions or, uh, you know, other, other software that we don't have on the truck that outside of those 60, and the rest of that is, is a paid plan.
But there's a way for you to kind of try and experience chain guard's value, um, without having to, without having to contact contact sales. So please check that out. I love it.
People like to check stuff out without having to contact sales. You and I know that. Mm-hmm.
Julian, then it's great seeing you. Now that I know you're here, I expect to have yarn here a lot more off. I'll definitely try to make that happen.
Alan, it's good to see you again. All right. Right, friend.
You be well. Good luck. You.
Sounds like you guys are running on all cylinders there, so it's all good. Chain guard, Julian Dunn, senior director of Product Manager in here on Techstrong tv, and we're gonna take a break. We'll be back with more.
Hello and welcome to the AI Leadership Insight series. I'm Amanda Ani, and with me today I have David Caruso. He is the Vice President of Financial Crime Compliance at Work Fusion.
How are you doing? I'm doing good, Amanda. Thanks for having me.
Thank you for coming on the show. Can you share a little bit about Work Fusion and what services do you provide? Sure.
So Work Fusion is an AI agent company, and we focus solely in one space, which is financial crime compliance. Uh, so we have agents that help financial institutions of all types and sizes from the US and around the world, uh, execute a lot of the daily tasks that are required in order for them to comply with all the various laws and regulations that they have to comply with. Just one example, uh, that's been in the news a lot over the last few years.
Whenever you, uh, read about the US government sanctioning to a Russian oligarch or, uh, anyone like that, financial institutions have to search all of their records and determine whether or not they bank those people. Well, that can be very onerous, very manual in nature. W among what we do is we provide AI agents that perform those tasks and do that work that allows banks to comply with those, uh, US and other, uh, rules and regulations very quickly, very efficiently, and, uh, yet, you know, much less cost.
Okay. Yeah, that's a, a big challenge, I imagine. So our topic for today is artificial intelligence and how it can be used in financial crime prevention, anti mo, anti-money laundering and compliance.
So from your experience, let's first talk about what are some of the biggest issues and concerns, um, when it comes to money laundering and compliance? Okay, well, the one issue that has existed since any of these rules and regulations went in place, and some of them are 50 years ago, is every year there's more money laundering and there's more fraud. So it just, this sort of, the nature of human beings, there's a lot of opportunity, there's a lot of money, there's a lot of crime.
And unfortunately, all of that at some point involves financial institutions. And my SF financial institutions. You can think of banks that we know, but also a lot of new company payment companies, a lot of FinTech companies.
So it's sort of anything that moves money, uh, or has a customer is, is prone to this. So with this increase in crime that unfortunately continues, uh, there's a great need for a lot of people to help financial institutions either prevent this ideally, or if they can't prevent these types of customers and activity, they have to detect it and report it, uh, by law. And so traditionally that's meant that year over year financial institutions have to hire more people, invest in more systems, and AI is impacting that because AI is now able to do much or i I say, significant amount of, uh, the work that's involved in detecting, investigating and reporting, you know, this activity.
And I'm happy to talk more about that, uh, or, you know, take it any direction you'd like to go. Yeah, absolutely. I'd love to hear some actual, um, use cases for AI in assisting.
Okay, sure. Like I, I mentioned at the top of our conversation, uh, there's a lot of work that's involved in what we, in the industry call screening. Uh, maybe many listeners are also familiar with the concept known as KYC or know your customer.
That's a concept that seems to have made it into just for the general, you know, average citizen discussion these days. And so in tho those areas of screening, uh, a lot of this work, and you can imagine, I just think about how many people there are on the planet, how many people want banking relationships or financial relationships. When those customers, uh, sign up for accounts, they have to go through, you know, what's called an onboarding process.
Well, AI agents can accelerate that. They, they automate much of it. Let's just take for an example, uh, where a customer might snap a photo of a passport or a driver's license.
Well, AI can extract all the information on that, right? It can, it can read the license, it can read the passport, it can identify things like dates of birth, addresses, uh, names. And so what a agents can do is they obviously can do that much better, much, much faster than a person can.
And so that's just one element of, of knowing the customer. Uh, other, other use cases involve actually detecting potentially suspicious transactions. So let's say that they, they are a customer of the bank.
They've gotten through the KYC system, but they're actually, maybe they're who they say they are, but who they are is actually a bad person. The bank just doesn't know that yet. So they begin to engage in activity that can be suspicious.
For example, a lot of cash activity or maybe wire tra uh, unusual amounts of wire transfer activity to all different parts of the world that, uh, in those parts of the world might be associated or have a, you know, a history of being associated with corruption and crime. Uh, so there are analog systems that detect that. But the problem is those analog systems, and what I mean by that is technology that's 10, 15, 20 years old, they detect a lot of that activity, but unfortunately, much of that activity isn't actually suspicious.
It's, it's, it's acceptable. It's, it's non suspicious. But banks have to hire, you know, collectively, hundreds of thousands of people are working on matters today, sorting through this, uh, these transactions.
And AI can just sort through those transactions, can spot patterns faster, can expand the networks of people that might be involved in that activity, uh, at a rate that human beings just simply can't. So, you know, it, it, it, it's better at detecting, uh, now it's interesting is a lot of this detection is what we in the industry call level one. So a lot of it's that sort sorting through, it's finding the things that might require more, more time, uh, more experienced people to look at.
So what we're doing is we're presenting those matters to the person, the, the trained investigator or analyst, uh, faster. And in some cases, a lot of the rudimentary document and information gathering that they would spend unfortunately hours doing well now that's in front of them so they can spend time, you know, making decisions, rendering judgment, uh, and hopefully stopping the growth of crime. So what would be considered level two or three?
And does AI have a, a use in those levels? Yeah, absolutely. Uh, and I, I've been in this field for about 30 years, financial crime compliance, but not all of it in technology.
Much of it on the operations side, doing the type of work that I'm describing to you. And just as we see AI improving in every aspect of ai, whether we'll just use it for our own purposes, uh, just to, you know, plan a vacation or, or, or whatever. It's so, so that same sort of improvement we're, we're seeing similarly in our space.
So to answer your question, yes, that level two work that requires more decision making, it more of that can be done as well. Uh, so yes, because like most things, uh, well, like many things, ultimately what we're looking for in our field is patterns, is, you know, are, are, is this activity indicative of a pattern that we know to be likely to be money laundering or fraud? And so the AI can surface those patterns, which is again, be more level two type work.
Uh, and yes, you can have, you know, large language models can now draft reports. You know, as you might imagine, there's a lot when you're reporting activity to the government, there's a lot of requirements around what you have to write, how you have to tell a story. And so yes, there, there's, there's that sort of level two capability is, uh, you know, so it's here already.
Uh, and I would say if we had, if we spoke next year at this time, it, the rate of of improvement would be significant. It's interesting as we talk about using AI to solve these issues, I would imagine on the flip side of that, that a lot of these threat actors are using ai, um, and making all these crimes a lot easier on their end as well. Yes.
And, and one of the ways in which they do it is they create what sometimes is referred to in the industry as Frankenstein I IDs. So in other words, they don't create entirely fictitious people or companies. They'll actually take stolen information or, or misappropriate information about a person or a business entity.
So it's, it's true ish. 'cause there's some things in there that can be validated, but then there's other information that isn't, it's synthetic, it's, it's created. Um, and that's able to get past a lot of sort of that onboarding review and, and screening.
So, 'cause re remember the how money is moved, that that hasn't changed that much over the years. Now, it can be moved much faster, you know, almost instantaneously now, whereas in years past, it might take anywhere from three to five to 10 days for financial transactions to be settled. So they are taking advantage of this almost instantaneous settlement.
But ultimately what they want is they want that instantaneous settlement, but they also wanna mask who they really are. So you, you sort, you're, they're, so, yes, there's, uh, and you know, as consumers, as honest law abiding consumers like you and I are, Amanda, we, we want instantaneous transactions, right? When I send my children money, they want it now.
So, so the things that we're demanding as consumers, yes, the, the, the bad guys can, can avail themselves of those same conveniences. So some of it isn't necessarily, they're creating new means and methods to, to commit fraud or launder money. They're just riding along the same rails we are.
So, and of course, financial institutions have to constantly balance the desire to give those features to customers who want them, along with the risks that those features, uh, will create. From your experience, what are some of the challenges that financial institutions face when they're implementing AI technologies? Uh, well, I think one of the challenges is simply that, and it's sort of a, a contradiction or what I'm about to say is, is that the reason that financial institutions do this is the, the by law they have to do it.
So it's, it's a highly regulated environment that in however, that, that regulation also slows things down. So, on one hand you have regulators saying, banks, you have to keep pace with this. You have to modernize.
And if that involves adopting ai, so be it. But in, before you adopt ai, you have to have very, uh, well-defined, uh, strategies for how you will do that. You have to put in a lot of governance above it.
So in a way, you have the, on the one hand saying, get at it, put in new technologies, and on the other hand is, but don't do it so fast that you do it poorly or actually increase the risk. So there, there is some, you know, that again, that's existed forever in the regulated, regulated world. Uh, but I would say it's probably a little more heightened now, uh, because there's, everyone sees the rate of improvement with AI and realize that, that we have to adopt this.
So how do we do it, uh, wisely and safely without falling behind, you know, our peers and, and what the regulators expect from us. Yeah, absolutely. Well, AI is advancing quite rapidly.
So what do you envision as the future of AI in regard to financial institutions and crime prevention? Well, as far as financial institutions writ large, that, that's a whole nother multi-hour conversation. Uh, because, you know, there's a lot of just how, how our banks and financial institutions operate.
You know, many of them still operate on very outdated and antiquated systems. So, um, the financial crime professionals within financial institutions don't, don't typically drive that modernization. So, but, but, so they'll have to follow that.
But, but separately, um, yeah, there, there are sort of obviously the, the, the agent AI technologies can be adopted. Uh, I do think it's gonna change a little bit. You know, A A ML compliance is about 20, 25 years old.
There's been a lot of ways in which those operations have been developed and staffed, uh, over those 25 years. I think AI is going to force a lot of executives and management in the space to rethink how their staffed, uh, the, the, the, the specific skill sets that are needed. So, you know, there, there's a lot of change coming, some of it from AI itself, and then much of it from the second and third order impacts from ai.
Alright. Well, if there was one key takeaway you could leave our audience with today, what would that be? Uh, that there's been, for the last five to 10 years, there's been a lot of discussion about what will happen, you know, what how, how what will happen when we see the technology, the technological change, uh, that a lot of people talk about.
Well, that change is here now. And, you know, for someone who's been in the industry as long as I have and has heard about this for as long as I have, there does remain probably some level of cynics cynicism or skepticism. But that should be in the past.
I mean, this, the things I've talked about today are happening today and financial institutions all over the world, they are deploying ai, uh, you know, all the components of ai, machine learning, natural language processing. So the takeaway should be, uh, if you're in this space and you're not availing yourself of, of ai, then you are going to be falling behind your peers. And when you operate in a regulated environment, falling behind your peers is, is, is a bad place to be.
All right. Well, thank you so much for coming on the show and sharing your insights with us today. Thank you, Amanda.
All right. And thank you to our audience. Stay tuned.
There's more. Welcome back to Tech Tech on TV guys and Lisa Martin. Great to be with you.
We are live at RSAC in San Francisco at Moscone West, having great conversations with leading cybersecurity experts across industries. For the next four days of live coverage, Alan Shimmel and Mitch Ashley will join me in the next couple of days. So be sure to keep tuning in.
My next guest is Chris Weal, chief security evangelist at Veracode. Chris, great to have you on Touchstone. Hi.
It's great to be here. You Are an OG cybersecurity expert. You've been in cybersecurity space for probably, you said, you mentioned like at least 20 RSAs.
That's Right. Talk to me about the evolution you've seen, because as technology advances, the good guys have access to it. Yep.
Bad actors have access to it. We've got, we're in this AI era now, which just spreads that attack surface even more amorphously. Absolutely.
What have you seen that struck you over the last 20 years? Well, I mean, I think we keep making the problem harder and harder for ourselves, Uhhuh, because we keep making more software. We keep expanding our attack surface.
Someone was telling me today that, um, there's risky plugins for teams Now. I'm like, really? There's plugins for teams.
So like, there's just more and more software coming at us constantly being deployed and all of that software has risk. Yeah. And now we have AI generating code Yes.
Which means more software faster. Yes. Um, so I, you know, that's, that's what we have to do as a cybersecurity industry, is protect this evolving attack surface.
Yeah. Which the technology changes. And, you know, the developers build new stuff, they change technologies on us.
And I always feel like security is always catching up. Okay. But I do think we're making good progress.
Yeah. Good. When I, when I, when I, when I spoke earlier today, my talk was secure by design.
Are we winning? Yeah. And what I wanted to show was there are some, there is some good news, there are some good indicators.
And we derive this data from Veracode's customers, we call the state of software security report. Yep. And in that data, it actually shows that over the last 15 years, there's less vulnerabilities in the software that vendors are producing.
That's good. And it actually was very slow, incremental progress for the first 10 years of the report. One 1% a year improvement in apps that didn't have one of these au top 10 vulnerabilities in them.
Okay. But in the last five years, we had 4% a year improvement. So we went What account For that acceleration?
Yeah. Well that's what I wanna figure out. Right.
Okay. Right. Right.
I mean, it's, it's great to see the outcome. Yeah. And then you try to figure out like what are the practices people are doing?
What are the motivations that is causing them to make better software? Right. And then, you know, I would say like, let's have more companies do that.
Do you think that's a DevSecOps Absolutely. Evolution. Absolutely.
And developers and security folks finally coming together to collaborate A Absolutely. I think the DevSecOps process gets that security more closely embedded into the actual Yeah. Development workflow and the whole shift left.
Yeah. And it's not the only answer, but it is definitely one of the things that you need to do to make improvements. And that has been a process change that's really taken hold in the last five years.
Oh yeah. Well, it's culture too. Right?
So I think that is one of them. Yeah. Developers are very aware of the security tools that are running now, where 10, 15 years ago it was something that someone else did.
And, you know, they, they pressured me to maybe fix a few flaws and I didn't really understand it. Now with DevSecOps, the improvement is, it's part of their job and, you know, we're, we're getting there. It isn't absolutely part of every developer's job.
Sure. But, um, I like to say it's part of the definition of done software is Yeah. The features are in there, they've been tested and they work and it's been security tested and the security bugs fixed.
Yes. Now it's done. And so that process improvement is what's making one of the big improvements in, in this outcome.
That's Good. It's, I'm sure you were pleasantly surprised to see that increase after 10 years of, of very small incremental Right. Improvements.
You Jump 1% a year. I was like, and we were starting at, uh, I think it was 23% passing rate and we got to 32% after 10 years. I was like, I'm gonna be long retired.
Yeah. Before we get to over 50%. Yeah.
But then we had this acceleration in the last five years, and I feel like we can actually improve things a lot over the next five. Well, the, the challenge, it's kind of like a, it's a flywheel, right? I I mean we're, you talked about we have so much more software now.
Right. But that phenomenon is only accelerating. Absolutely.
It's not gonna, gonna slow down. So how does Veracode help get control for the developers? So from a business perspective, nobody wants to be the next headline.
Is it possible to gain control over this? So yes. But it isn't something that happens overnight.
And one of the big reasons is when you first test your software, you have years and years of security debt, all that time. You weren't testing the software. You had vulnerabilities that you were completely ignoring.
You didn't even know they existed. Right. And then you, so you sort of have to slowly drive down that security debt.
You have to take, allocate a percentage of time. 'cause you can't do it all at once. You can't, like, um, I know Microsoft said they did this back in like 2003 with their trustworthy computing memo.
Bill Gates said, we're gonna stop writing software. Everyone's gonna learn how to write secure software. We're gonna fix all the bugs.
Mm-hmm. It's like, you just can't stop your company for a year, let alone a month. No.
Right. You have to weave it in. Yeah.
And you have to, you have to have to slowly drive, drive that debt down. So that's what we do when we start engaging with a customer, is we put these tools in place, but we say you can't, you still have to keep shipping your software. Yeah.
And unfortunately, you're gonna be shipping software, whether it's to the cloud or to your mobile device or to your customers. OnPrem that has that has security bugs in it. Yeah.
'cause you can't fix them all right away. Right. Right.
But the, the, what you wanna get to is have enough capacity to fix at least the bugs that you're, the new bugs you're creating. So you sort of stop the bleeding Yeah. And you're not getting worse.
Yeah. And then you incrementally make, make pro process. So it, it typically takes a company a few years Okay.
To go from no process to being best in class. Okay. I would say like four or five years.
Oh, okay. So that's a journey. Yeah.
It's a journey. As the, the evangelist. Where are you having conversations within customers?
Is it at the CSO level? Is it at the ELT level? Is it the developers?
All the Above. It's, it's mostly with the developers. Okay.
Um, and that's great because like all the security people already know who I am. They know who Veracode is. They know what we do.
Um, but the developers have no idea. Right. So like a company will have a developer day where they'll fly all their developers to one location and they'll have talks throughout the day.
I love speaking at those talks. 'cause I get to engage directly with, it might not be the developers, it might be sort of the development managers. Okay.
That would be developers and architects too. But that's your audience. And that would, that would be the audience that I really like to like, to talk to Talk a little bit about, you mentioned the Secure by Design campaign is CISA launched that what, a couple of years ago?
Yes. It's been a couple years now. Yeah.
It's been a couple years. They launched their, uh, secure by Design Pledge Two years ago. What's the, what's the conceptually Philosophical.
So Secure by Philosophical by Design has been around for a long time in, in my talk. Um, and my co-presenter, actually Jason Healy, he's from Columbia. He's a security researcher.
He talks about, uh, a paper written by the Air Force in 1972 that actually said, we have no hope to build secure software unless we start from the beginning and build it secure by design. Oh, okay. So the concept isn't new.
Got it. It's just that people haven't been practicing it. Why do you think that is?
Is it behavioral? Because when you start building software, that's the time where time is the most precious. Mm-hmm.
Right. You're like trying to see if you can get the software to market. Yeah.
It might be a competitive situation where you're doing catch up with your competitor. I mean, the competitive pressures is the big reason Sure. That people aren't fixing flaws 'cause they need that feature.
Right. Or they have a customer complaining about something. So when you have those scenarios, the fixing a security bug becomes deprioritized.
And I, and I think the Secure by Design is deprioritized because it's in the beginning of when you're building software, but unless you do it, you kind of have no hope over the lifetime of that software of having it be really secure. Right. It's really hard to bolt stuff back.
Right on. Like, if you look at what Adobe did with Flash, I dunno if you remember, but there was years after years of critical bugs and Adobe Flash. This was really old software.
Adobe Flash was created in the late nineties. Yeah. And it persisted until, I don't know, like 2015 or something like that.
And they finally said, we can't keep up with the bugs. Wow. We're gonna, we're gonna, we're gonna, we're gonna terminate this software and and we're gonna shut it down and end of life it.
Yeah. Um, that's an extreme case. Yeah.
But it, it, it, it sort of shows the point because they didn't build it securely in the beginning and it was very popular, very critical piece of software and all kinds of websites. Yeah. Um, it was constantly attacked and they could never, couldn't catch up.
So that's sort of the worst case scenario. Um, but, but that's, that's, that's what can happen if you don't start secure by design. Well, it needs to be baked in from the beginning.
Application security. Where does that belong in production? It can't be a bolt on afterthought because we've companies time and again, have proved that doesn't work.
Right. Like the worst, the worst place to put it is like, well, maybe just scanning stuff after put it into production. Yeah.
That would be the worst. But people, most people realize that, that that gives no time to fix anything that you find. So, uh, a lot of companies scan the code or test the code just before production.
Okay. But the problem is with DevSecOps, with so many quick iterations where you might be pushing code on a daily basis, there's no time to both test it and fix it and fix it. So you gotta, this is where the whole shift left comes in.
Ideally in the cust in the, in the developer's IDE or at pull request time when that code is changing, test it. Yeah. And you have the opportunity to fix it.
Yeah. Then, then too. But I think that that also is a little shortsighted just to shift left, because so we say you have to shift right too.
Like you have to understand what's going on in production. Sure. Because there's stuff in production that doesn't exist on a developer's desktop.
Okay. It's interacting with the cloud environment that might be configured differently. There might be other software deployed in, in that, in production that it's interacting with.
So you need to test there too. Sure. So we say shift left and right.
Okay. Both as early as you can and in and, and in production to give you that complete continuously Picture. Yeah.
And that's one of the things that we're driving to at Veracode. We have this product called Veracode Risk Manager, which connects results found in production back with the results of your testing. Okay.
Back with the code and the root cause of the problem to, to, to make one coherent picture of risk and where to fix it. The best place to fix issues. So instead of fixing a hundred individual issues, if you can determine it's really just one issue.
Yeah. You wanna do that? Yeah.
Go upstream. So that, and, and so that's, that's our drive is to constantly make things more efficient for the developers. Yeah.
'cause we know their time is so limited. Yes. Yes.
So we want the context point them Right. To the fix. And now we're introducing ai, generative AI based fixing.
Okay. So have the AI fix it. Yeah.
And if you think about, like we, we talked about velocities are getting quicker and quicker. There's more code. Generative AI is just making that go faster.
Exactly. Right. So I've seen data that say each developer can write 50% more code, um, using generative ai.
Yeah. So now you have 50% more code per developer who's gonna fix the flaws. Right.
'cause we can't, we can't Just expect it's gonna be secure. So you need to Right. You can't assume that the generative AI stuff is secure.
So we gotta test that just the same. But then you need something that can fix it. Yeah.
And so we are focused on automating the fixing process using jitter AI as much as possible and make things that are reliable and built in that just maybe every time vulnerabilities are found in a pull request, automatically fix them. Yeah. It sounds like what you're giving the developers is visibility.
Yep. Way more visibility than they had before to really understand where things are, where the vulnerabilities are, how to fix them, allowing them to, to use gen AI to be more productive. Which is what they want.
They wanna write code EE Exactly. They wanna generate app. They want To vibe code.
Yeah. They want vibe code. Yeah.
Who wants to look up for what this API's I know are That's so hard. He already knows it. Yeah.
Just say, I wanna make a database call. Yep. Yep.
Yep. What's your favorite customer story of Erica that you think really shines a light on the true value you are delivering so that organizations can really become cyber resilient? That's a journey in and of itself.
Yeah. So I, I think the way I like to look at it is, if we look at our state of software security report, which we came out in 2025, um, we, we, we look through the data and we have, you know, we have a lot of averages. The average application, the average bug takes this long to fix.
The average application has this many percent of OAS top 10. But then we split it into quartiles and we said, what are the organizations that are leading, what are the ones that are doing the best? Yeah.
And so it, it shows you what you as a organization, you can benchmark yourself against this data and say, I, I want to improve. I want to be like that. So that's, that's sort of the story I like to tell is, you know, the, the best organizations are fixing 10% of all the security bugs they know about Okay.
On a monthly basis. And is that acceptable? 10%?
Yes. That will keep you your head above water. Got it.
That'll keep your head, that'll keep your head above water. Um, so, so we look at those metrics of the leading organizations, like how fast are they fixing flaws? Is it taking them six months a year, or is it taking them 30 days?
And then it shows you like, well you, it's, this is possible. Yeah. This is possible to do.
Yeah. I would love to add in survey data Yeah. To say like, exactly how are you getting to these outcomes?
Sure. Because we just see the outcome in the data. Okay.
We don't know what they're actually doing. That Would be nice insight to have. Yeah.
So I, I would love, love to do that to tell a better story. So a a a customer or just any company can, can look at our, our report and say, if I do these things, I'm gonna get an outcome like this. Right.
And I don't have to just like, listen to something as a best practice. This is what companies that are getting these good results are actually, are actually doing. And I think that's can connecting practices with outcomes Absolutely.
Is super important. 'cause we, everyone here speaking in all these halls is talking about what's the best way to do this? What's the best way that, but they have to show that the actual outcomes are real world companies.
Yes. Or it's just a pipe dream. It's all about outcomes.
Yeah. Last question for you. As we're living in this AI era, you know, it's funny, AI's been around for decades, but chat GPT was born and then everybody is talking about AI and it's, there's a lot of AI washing going on.
You can't go to a conference without hearing tons about ai. But how in this AI era, you know, organizations, I talk to CMOs a lot, or everybody's embracing gen, ai, agent ai. How do you help organizations defend this digital frontier and the age of AI when the frontier is just continuingly changing?
Right. One of the challenges is just knowing where the AI is. Yeah.
Right? Like a lot of it is like it's creeping into all these different products. And like sometimes CISOs are completely surprised that something has been transcribing all of their employee video conferencing calls.
Yep. Right. Oh.
'cause anybody can shadow it. Anybody can. Yeah.
You can just use order or zoom every, everything's got note takers. Totally. So it's again, this AI attack surface Yeah.
Is percolating through, through everything. And, and if say you're using a SaaS service and you're sending your data out of your enterprise somewhere else to be processed, right. Are are they training on my data?
Mm-hmm. Right. Is there a chance that my, my, my secrets end up in, in the answer to someone else's support question.
Yeah. Right. So that's, those are the things you need to ask or CISOs need to ask Yeah.
Is where is all this AI Yeah. Activity happening? Because a, all AI has to learn from something, right?
And there's so much value in AI learning from proprietary data sets. 'cause everyone can train on the o open source code or all the, you know, published books out there. There's a lot of stuff they're not supposed to be training on, but there are.
But there are because it's because it's available. Right. But if you have a proprietary dataset, you, that gives you a competitive advantage.
Okay. And what's a great one? Like the data my, my customers are creating, right?
So this is, this is one big thing that people need to be aware of. The other one is, where is AI being built into my own software? Right?
Like, if I'm building a chat bot for my website is are they hooking in Yeah. Chat G-P-T-A-P-I into that thing and they're having it, it, it, it talked, you know, that's a risk. Now I have can have things like prompt injection.
Right. Maybe attackers can get into my proprietary data through the chatbot Yeah. My website.
Yeah. Because it has access to my customer records or something like that. So there's a risk of losing your proprietary data and there's a risk of, um, you know, by people training on it, but there's also this risk of attackers Yeah.
Using the AI you're building in to steal your data. Wow. So it's, it's a new it.
I I feel like it's the cloud era all over again. Okay. Where cloud changed everything.
Sure. I think AI is changing everything again. Yeah.
What's the one positive that you can share with the audience that, that you've seen from this evolution that we talked about at the beginning of cybersecurity? What's the golden nugget? We're going in the right direction here.
I think we are going in the right direction. Um, and, and, and the, so the big picture is like as this technology constantly changes, is it helping defenders more or is it helping offense Right. More.
Yeah. Right. And we have to constantly think like, how does, how, how, how does defense constantly, constantly get better?
Right. And one of those things is, is secure by design. Yeah.
Right? That is, that is something that, that helps the defense get better because you have more defendable software, less vulnerabilities, less patching, less incidents to respond to. Right.
So, um, I, I think the, the secure by design is definitely the biggest thing that I'm seeing as a, as a, as a, as a potential game changer. Excellent. Um, but I also think that this connecting the dots of, um, the technology with the root cause of the problems.
Yeah. So this attack surface management discovering vulnerabilities, but then connecting it back to the root, the root problem. This is giving us much better visibility.
Exactly. I was just Yes. In into risk.
So the visibility into risk is, is getting, getting better, getting, but we have to act on it. Yeah. Right.
Like, that's, that's that, that's, that's a Yeah. But y then you have to make improvements based on the information you have. Yeah.
You can't just get this great information then do nothing with it. Right. It's a never ending story.
Yeah. Chris, thank you so much for joining me on Techstrong TV today. I learned so much from you.
What you're doing at Veracode, what you're enabling developers to achieve. That visibility, those blinders are coming off that's so important as cybersecurity will just continue to evolve in good ways and not so good ways. Gotta stay a step ahead.
We appreciate your insights. Thank you for joining me. Thank you so much for having me.
Oh, my pleasure. For Chris Wise Sopel, I'm Lisa Martin. You're watching Techstrong tv, live from R-S-A-I-C.
This is day one of four days of coverage from techon. Keep it on this channel. We've got more great content coming up.
Thanks for watching.